DisclosureLens
NORTH CAROLINAAccidentalHealthcareFinancial ServicesHealthcareMisdeliveryCustomer Data InvolvedIdentity (basic)Health (basic)LowResolved

Blue Cross and Blue Shield of North Carolina

bd_dbddf78a3f27d0c3 · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Nov 7, 2013

To disclose

Affected

687

Confidence

98%
Full breach record for Blue Cross and Blue Shield of North Carolina5 incidents on file

On October 14, 2013, Blue Cross and Blue Shield of North Carolina (a Health Plan, NC) impermissibly disclosed the PHI of 687 individuals when an employee inadvertently mailed policy change notices to incorrect addresses. PHI involved included names. The CE was submitted to HHS on 2013-11-07. Breached information was on Paper/Films. No business associate was present. Following OCR investigation, the CE provided media notice, established a toll-free number, sanctioned the responsible employee, retrained staff, and initiated regular review of mailing procedures.

HIPAA clock HHS notified
no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
⚠ No discovery dateThe OCR public portal omits the discovery date, so the 60-day notification clock cannot be evaluated from this source — only that the filing was submitted.

Incident timeline

Oct 14, 2013

Begins

Nov 7, 2013

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed687 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.