NCAccidentalHealthcareFinancial ServicesHealthcareMisdeliveryCustomer Data InvolvedIDENTITY_BASICHEALTH_BASICLowResolved
Blue Cross and Blue Shield of North Carolina
bd_dbddf78a3f27d0c3 · schema v1 · pii pii-v1
Full breach record for Blue Cross and Blue Shield of North Carolina →On October 14, 2013, Blue Cross and Blue Shield of North Carolina (a Health Plan, NC) impermissibly disclosed the PHI of 687 individuals when an employee inadvertently mailed policy change notices to incorrect addresses. PHI involved included names. The CE was submitted to HHS on 2013-11-07. Breached information was on Paper/Films. No business associate was present. Following OCR investigation, the CE provided media notice, established a toll-free number, sanctioned the responsible employee, retrained staff, and initiated regular review of mailing procedures.
HIPAA clock✓ HHS notified
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
⚠ No discovery dateThe OCR public portal omits the discovery date, so the 60-day notification clock cannot be evaluated from this source — only that the filing was submitted.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed687 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Nov 7, 2013
- Raw hash
- 279451585bfe4152db8833cc8d5c92dcc871760f4ae7c27adb8776d23b6debf8
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Blue Cross and Blue Shield of North Carolinanorm: blue cross and blue shield of north carolina
- Domain
- bcbsnc.com
- Industry
- Insurance — Health
Victim entity
- Name
- Blue Cross and Blue Shield of North Carolinanorm: blue cross and blue shield of north carolina
- Domain
- bcbsnc.com
- Industry
- Insurance — Health
- Industry
- Healthcaresource defaultFinancial Servicesllm
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 687
- Data types
- IDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unauthorized Access
- Threat actor
- Internal
- Regulator citations
- HHS OCR investigation; CE required to provide media notice and establish toll-free number for affected individuals
- Initial access
- insider_action
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.