BLUE CROSS AND BLUE SHIELD ASSOCIATION
bd_78dfdb74dc4b65d4 · schema v1 · pii pii-v1
Full breach record for BLUE CROSS AND BLUE SHIELD ASSOCIATION →Blue Cross Blue Shield Association (BCBSA) disclosed a security incident involving its Federal Employee Program (FEP) mobile app. A vendor's programming change on September 28, 2019, inadvertently altered permission functionalities, allowing adult family members to view summary claims information of other policyholders between September 28 and October 22, 2019. BCBSA disabled the feature upon discovery on October 22, 2019. Exposed data included names, addresses, health insurance IDs, and summary medical/pharmacy claims. No SSNs, DOBs, or financial data were accessed. The incident was contained, and no misuse was reported.
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_c7eac7fe44baf049Montana State AGfiled 2019-12-12Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-185087
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 12, 2019
- Raw hash
- 44dadf9148dbaae01b32c8fb592a1e41a3548ecad1c3454fc0460d0bb5ca9234
Reporting entity
- Name
- BLUE CROSS AND BLUE SHIELD ASSOCIATIONnorm: blue cross and blue shield
- Domain
- fepblue.org
Victim entity
- Name
- BLUE CROSS AND BLUE SHIELD ASSOCIATIONnorm: blue cross and blue shield
- Domain
- fepblue.org
Incident
- Discovered
- Oct 22, 2019
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- HEALTH_BASICIDENTITY_BASIC
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1562 Impair Defenses
Compliance
- Time to disclose
- 7 weeks(51 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.