FEDERALAccidentalHealthcareHealthcareDisposal ErrorCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICHigh
Independence Blue Cross and AmeriHealth New Jersey
bd_e930925e21e0ac7b · schema v1 · pii pii-v1
Full breach record for Independence Blue Cross and AmeriHealth New Jersey →During an office move, the maintenance team for Independence Blue Cross and AmeriHealth New Jersey improperly disposed of paper records containing the protected health information (PHI) of approximately 12,450 individuals. The PHI included names, addresses, Social Security numbers, and other health-related information. The company provided breach notifications, offered free credit monitoring, and implemented new policies and training for staff regarding proper document disposal.
HIPAA clock✓ HHS notified
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
⚠ No discovery dateThe OCR public portal omits the discovery date, so the 60-day notification clock cannot be evaluated from this source — only that the filing was submitted.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed12,450 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Dec 26, 2014
- Raw hash
- 7b80650bcf66a08a1b073bd47afe961492cb32e7e95384d9dc35111baf310946
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Independence Blue Cross and AmeriHealth New Jerseynorm: independence blue cross and amerihealth new jersey
- Industry
- Insurance — Health
Victim entity
- Name
- Independence Blue Cross and AmeriHealth New Jerseynorm: independence blue cross and amerihealth new jersey
- Industry
- Insurance — Health
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 12,450
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Misconfiguration
- Threat actor
- Internal
- Regulator citations
- As a result of OCR’s investigation, the CE revised its policies and procedures.
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.