Blue Cross and Blue Shield of Massachusetts, Inc.
ent_019e206b0c72dbceb1ea2e4d3088f196
Disclosures
5
State AG · HHS OCR · 4 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
4,855
as filed · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Blue Cross and Blue Shield of Massachusetts, Inc.
- Normalized
- blue cross and blue shield of massachusetts— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 5493000TCTN0M1X5OU18
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (5)newest first
- 🐻California State AGas victim2025-07-07
Cierant Corporation, a distributed marketing software vendor for Blue Cross and Blue Shield of Massachusetts, disclosed a data security event involving a vulnerability in the third-party file transfer tool Cleo VLTrader. An unauthorized actor exploited this vulnerability to gain limited access to Cierant systems, potentially acquiring files containing personal information of approximately 1,422 Rhode Island residents. The incident was discovered on December 10, 2024. Cierant ceased use of the tool, rotated passwords, and is offering credit monitoring.
- 🐻California State AGas victim2024-01-08
Welltok, Inc., a healthcare technology vendor, disclosed that an unknown actor exploited software vulnerabilities in its MOVEit Transfer server on May 30, 2023, exfiltrating data including names, dates of birth, and health insurance information. The incident was discovered on July 26, 2023. Welltok is offering credit monitoring to affected individuals.
- 🦞Maine State AGas victim2022-07-20
Blue Cross and Blue Shield of Massachusetts reported a data breach that occurred on May 17, 2022, and was discovered on June 20, 2022. The incident affected 4,855 individuals, compromising names and Social Security numbers. Affected individuals were notified on July 20, 2022, and offered 24 months of identity theft and credit monitoring services from Experian.
- 🦬Montana State AGas victim2022-07-20
Blue Cross and Blue Shield of Massachusetts, Inc. reported a data breach to the Montana Attorney General. The breach was reported on 2022-07-20. The breach occurred on 5/17/2022. 2 Montana residents were affected.
- FEDERALHHS OCRas victim2017-12-26
On February 20, 2017, Blue Cross Blue Shield of Massachusetts (BCBSMA) erroneously emailed a data file containing the protected health information (PHI) of 1,843 individuals to one of its employer accounts. The file included names, addresses, birthdates, and social security numbers. The error was discovered on December 12, 2017, when the employer account used the incorrect data to send letters. Upon notification, the recipient destroyed the data. BCBSMA reported the breach to HHS on December 26, 2017.