Blue Cross and Blue Shield of North Carolina
ent_019e0a6f936b4fe9fb3797dc69cfee50
Disclosures
4
State AG · HHS OCR · 2 jurisdictions
Incidents
—
no linked incident in sample
Max affected reported
1,530
nationwide · HHS OCR NC
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Blue Cross and Blue Shield of North Carolina
- Normalized
- blue cross and blue shield of north carolina— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- E6Y85FWCOYHDXNFPPQ79
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- bcbsnc.com
Disclosure history (4)newest first
- 🦬Montana State AGas victim2024-08-27
Blue Cross and Blue Shield of North Carolina reported a data breach to the Montana Attorney General. The breach was reported on 2024-08-27. The breach occurred from 5/21/2024 to 6/19/2024. 972 Montana residents were affected.
- NCHHS OCRas victim2018-10-11
Blue Cross and Blue Shield of North Carolina reported to HHS on 2018-10-11 a Unauthorized Access/Disclosure affecting 631 individuals. Breached information located on Paper/Films. The entity mistakenly sent low income subsidy (LIS) letters containing another member's name and ID number to the wrong members due to an employee's failure to follow quality review procedures.
- NCHHS OCRas victim2015-09-11
Blue Cross Blue Shield of North Carolina reported to HHS on 2015-09-11 a Unauthorized Access/Disclosure affecting 1530 individuals. Breached information located on Paper/Films. Business associate EDM Americas accidentally sent invoices containing other members' PHI (names, addresses, account numbers, coverage dates, premiums) to members.
- NCHHS OCRas victim2013-11-07
On October 14, 2013, Blue Cross and Blue Shield of North Carolina (a Health Plan, NC) impermissibly disclosed the PHI of 687 individuals when an employee inadvertently mailed policy change notices to incorrect addresses. PHI involved included names. The CE was submitted to HHS on 2013-11-07. Breached information was on Paper/Films. No business associate was present. Following OCR investigation, the CE provided media notice, established a toll-free number, sanctioned the responsible employee, retrained staff, and initiated regular review of mailing procedures.