BLUECROSS BLUESHIELD OF TENNESSEE, INC.
ent_019e0b0496363d19fb930d023b7ddb89
Disclosures
13
HHS OCR · State AG · 6 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
1,023,209
nationwide · HHS OCR TN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- BLUECROSS BLUESHIELD OF TENNESSEE, INC.
- Normalized
- bluecross blueshield of tennessee— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 5493006U38WE57A0PZ94
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- bcbst.com
Disclosure history (13)newest first
- TENNESSEEHHS OCRas victim2026-02-11
BlueCross BlueShield of Tennessee, Inc., acting as a business associate, reported a Hacking/IT Incident affecting a network server. A subcontractor of its covered entity experienced the breach, which the BA reported affected approximately 37,402 individuals overall (HHS portal row attributes 1,670 to this filing). PHI involved names and other identifiers. BCBSTN notified HHS, affected individuals, and the media, and offered free credit monitoring. OCR provided technical assistance regarding the HIPAA Rules.
- TENNESSEEHHS OCRas victim2025-12-26
BlueCross BlueShield of Tennessee, Inc. reported to HHS on 2025-12-26 a Unauthorized Access/Disclosure affecting 780 individuals. Breached information located on Email.
- Montana State AGas victim2024-05-23
BlueCross BlueShield of Tennessee notified individuals of a privacy issue discovered on March 19, 2024, caused by human error. An employee mistakenly emailed a spreadsheet containing personal and health information to another insurance company. The recipient certified deletion. Affected data includes names, DOB, subscriber/group IDs, and claims info. The company provided HIPAA training and offered free credit monitoring via Experian.
- TENNESSEEHHS OCRas victim2024-04-05
BlueCross BlueShield of Tennessee, Inc. reported to HHS on 2024-04-05 a Unauthorized Access/Disclosure affecting 717 individuals. Breached information located on Network Server. The BA inadvertently posted PHI to the Internet.
- TENNESSEEHHS OCRas victim2023-12-19
BlueCross BlueShield of Tennessee, Inc. reported to HHS on 2023-12-19 a Hacking/IT Incident affecting 1676 individuals. Breached information located on Network Server. A vendor of the entity's business associate experienced a cyber-attack compromising PHI including names, birthdates, claims, financial info, and treatment data.
- TENNESSEEHHS OCRas victim2023-07-25
BlueCross BlueShield of Tennessee, Inc. reported to HHS on 2023-07-25 a Unauthorized Access/Disclosure affecting 2688 individuals. Breached information located on Paper/Films. Due to a computer error, an employee inadvertently mailed PHI to wrong recipients.
- Massachusetts State AGas victim2021-01-06
BlueCross BlueShield of Tennessee, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-01-06. 3 Massachusetts residents were affected. The report records the breach type as electronic.
- TENNESSEEHHS OCRas victim2020-12-18
BlueCross BlueShield of Tennessee, Inc. reported to HHS on 2020-12-18 a Hacking/IT Incident affecting 1340 individuals. Breached information located on Email. A business associate employee was victim of an email phishing scheme exposing ePHI including names, addresses, SSNs, and treatment info.
- Maine State AGas victim2020-12-18
BlueCross BlueShield of Tennessee, Inc. reported a data breach affecting 3 Maine residents. The breach was discovered on November 9, 2020, and occurred between June 24, 2020, and July 1, 2020. The breach was due to unauthorized access at their vendor, EyeMed. The information acquired includes names and Social Security Numbers. Identity theft protection services are being offered for 2 years through Experian.
- Illinois State AGas victim2020-01-01
BLUE CROSS BLUE SHIELD OF TENNESSE, INC. filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-533). The register records the breach as discovered on September 28, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- TENNESSEEHHS OCRas victim2017-07-21
BlueCross BlueShield of TN, Inc. reported to HHS on 2017-07-21 a Unauthorized Access/Disclosure affecting 2117 individuals. Breached information located on Paper/Films. The entity erroneously mailed a monthly report to employer health plan administrators that included the PHI of members enrolled in another group due to a software discrepancy.
- TENNESSEEHHS OCRas victim2010-11-01
BlueCross BlueShield of Tennessee, Inc. reported to HHS OCR on 2010-11-01 a Theft incident affecting 1,023,209 individuals. The breached information was located on an 'Other' device/medium. No business associate was identified as involved. No further detail is available from the HHS web description.
- New Hampshire State AGas victim2010-03-31
BlueCross BlueShield of Tennessee reported the theft of 57 hard drives containing encoded (unencrypted) audio and video recordings of customer service calls. The theft occurred on Oct 2, 2009, and was discovered on Oct 5, 2009. Data included PHI, names, SSNs, and DOBs. Notification began Dec 7, 2009. ~311,000 individuals affected nationwide; 724 NH residents. Kroll OnTrack engaged for forensic review. Credit monitoring offered.