Blue Cross and Blue Shield of North Carolina
ent_019e0a6f936b4fe9fb3797dc69cfee50
Disclosures
7
State AG · HHS OCR · 2 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
1,530
nationwide · HHS OCR NC
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Blue Cross and Blue Shield of North Carolina
- Normalized
- blue cross and blue shield of north carolina— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- E6Y85FWCOYHDXNFPPQ79
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- bcbsnc.com
Disclosure history (7)newest first
- Montana State AGas victim2024-08-27
Blue Cross and Blue Shield of North Carolina notified members of a breach involving its 'Blue Connect' portal. Between May 21 and June 19, 2024, an unauthorized party used stolen credentials to access member accounts, obtain PII (name, DOB, subscriber ID), and create fraudulent accounts with wellness vendor Rally Health to redeem gift cards. Blue Cross NC reset passwords, removed DOBs from profiles, and engaged law enforcement.
- NORTH CAROLINAHHS OCRas victim2024-08-27
Blue Cross and Blue Shield of North Carolina reported to HHS on 2024-08-27 a Hacking/IT Incident affecting 972 individuals. Breached information located on Network Server.
- Montana State AGas victim2024-07-19
Qualtrics, LLC reported that an unauthorized party used compromised credentials to access a Blue Cross NC customer account on May 7, 2024, exporting a contact list containing names, emails, demographics, and health insurance IDs. Qualtrics locked the account, reset credentials, and notified law enforcement.
- NORTH CAROLINAHHS OCRas victim2018-10-11
Blue Cross and Blue Shield of North Carolina reported to HHS on 2018-10-11 a Unauthorized Access/Disclosure affecting 631 individuals. Breached information located on Paper/Films. The entity mistakenly sent low income subsidy (LIS) letters containing another member's name and ID number to the wrong members due to an employee's failure to follow quality review procedures.
- NORTH CAROLINAHHS OCRas victim2015-09-11
Blue Cross Blue Shield of North Carolina reported to HHS on 2015-09-11 an Unauthorized Access/Disclosure affecting 807 individuals. Breached information located on Paper/Films. The entity accidentally sent payment letters containing other members' PHI.
- NORTH CAROLINAHHS OCRas victim2015-09-11
Blue Cross Blue Shield of North Carolina reported to HHS on 2015-09-11 a Unauthorized Access/Disclosure affecting 1530 individuals. Breached information located on Paper/Films. Business associate EDM Americas accidentally sent invoices containing other members' PHI (names, addresses, account numbers, coverage dates, premiums) to members.
- NORTH CAROLINAHHS OCRas victim2013-11-07
On October 14, 2013, Blue Cross and Blue Shield of North Carolina (a Health Plan, NC) impermissibly disclosed the PHI of 687 individuals when an employee inadvertently mailed policy change notices to incorrect addresses. PHI involved included names. The CE was submitted to HHS on 2013-11-07. Breached information was on Paper/Films. No business associate was present. Following OCR investigation, the CE provided media notice, established a toll-free number, sanctioned the responsible employee, retrained staff, and initiated regular review of mailing procedures.