Blue Cross and Blue Shield of Massachusetts, Inc.
ent_019e206b0c72dbceb1ea2e4d3088f196
Disclosures
20
State AG · HHS OCR · 6 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
39,000
as filed · State AG MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Blue Cross and Blue Shield of Massachusetts, Inc.
- Normalized
- blue cross and blue shield of massachusetts— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 5493000TCTN0M1X5OU18
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (20)newest first
- Massachusetts State AGas reporting2025-07-18
Blue Benefit Administrators of Massachusetts reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-07-18. 61 Massachusetts residents were affected.
- California State AGas victim2025-07-07
Cierant Corporation, a distributed marketing software vendor for Blue Cross and Blue Shield of Massachusetts, disclosed a data security event involving a vulnerability in the third-party file transfer tool Cleo VLTrader. An unauthorized actor exploited this vulnerability to gain limited access to Cierant systems, potentially acquiring files containing personal information of approximately 1,422 Rhode Island residents. The incident was discovered on December 10, 2024. Cierant ceased use of the tool, rotated passwords, and is offering credit monitoring.
- New Hampshire State AGas victim2022-07-27
Blue Cross and Blue Shield of Massachusetts notified the NH AG of a data incident involving vendor LifeWorks US Inc. A former LifeWorks employee emailed spreadsheets containing PII (name, address, SSN, pension info) to personal email on May 17, 2022. BCBSMA learned of this on June 20, 2022. Affected individuals are offered 24 months of credit monitoring.
- Maine State AGas victim2022-07-20
Blue Cross and Blue Shield of Massachusetts reported a data breach that occurred on May 17, 2022, and was discovered on June 20, 2022. The incident affected 4,855 individuals, compromising names and Social Security numbers. Affected individuals were notified on July 20, 2022, and offered 24 months of identity theft and credit monitoring services from Experian.
- Montana State AGas victim2022-07-20
Blue Cross and Blue Shield of Massachusetts notified Montana residents of a data security incident involving vendor LifeWorks US Inc. A former employee emailed spreadsheets containing names, addresses, SSNs, and pension info to personal email accounts on May 17, 2022. Blue Cross was notified on June 20, 2022. Notices were sent July 20, 2022, offering 24 months of credit monitoring.
- Indiana State AGas victim2022-07-20
Blue Cross and Blue Shield of Massachusetts, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2022-05-17 and was reported on 2022-07-20. 2 Indiana residents were affected. 4,855 individuals affected in total.
- Massachusetts State AGas victim2022-07-12
Blue Cross and Blue Shield of Massachusetts, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-07-12. 3,561 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2020-10-22
Blue Cross and Blue Shield of Massachusetts, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-10-22. 7,937 Massachusetts residents were affected. The report records the breach type as electronic.
- MASSACHUSETTSHHS OCRas victim2019-02-15
Blue Cross Blue Shield of Massachusetts reported to HHS on 2019-02-15 a Hacking/IT Incident affecting 1262 individuals. Breached information located on Email. An employee of business associate Health Equity was targeted by social engineering, leading to phishing emails sent to contacts. PHI including demographic, financial, and clinical data was affected.
- Massachusetts State AGas victim2018-01-29
Blue Cross and Blue Shield of MA Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-01-29. 530 Massachusetts residents were affected. The report records the breach type as electronic.
- MASSACHUSETTSHHS OCRas victim2017-12-26
On February 20, 2017, Blue Cross Blue Shield of Massachusetts (BCBSMA) erroneously emailed a data file containing the protected health information (PHI) of 1,843 individuals to one of its employer accounts. The file included names, addresses, birthdates, and social security numbers. The error was discovered on December 12, 2017, when the employer account used the incorrect data to send letters. Upon notification, the recipient destroyed the data. BCBSMA reported the breach to HHS on December 26, 2017.
- New Hampshire State AGas reporting2015-03-20
Anthem, Inc. suffered a sophisticated external cyber-attack discovered on Jan 29, 2015. BCBSMA notified Nuance Medical Plan participants on Mar 2, 2015. Data accessed included names, DOB, gender, member IDs, addresses, phone, email, and employment info. No SSN or financial data compromised. Anthem offered 2 years of credit monitoring.
- Massachusetts State AGas victim2014-12-18
Blue Cross Blue Shield of Massachusetts reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2014-12-18. 1 Massachusetts residents were affected. The report records the breach type as paper.
- Massachusetts State AGas reporting2014-08-18
Blue Cross Blue Shield of MA reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2014-08-18. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas reporting2012-12-31
Blue Cross Blue Shield of MA reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2012-12-31. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas reporting2012-10-18
Blue Cross Blue Shield of MA, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2012-10-18. 23,116 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas reporting2012-07-19
Blue Cross Blue Shield of MA reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2012-07-19. 1 Massachusetts residents were affected. The report records the breach type as paper.
- Massachusetts State AGas reporting2011-12-08
Blue Cross Blue Shield of MA reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2011-12-08. 15 Massachusetts residents were affected. The report records the breach type as paper.
- Massachusetts State AGas victim2010-12-08
Blue Cross Blue Shield of Massachusetts reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2010-12-08. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2009-09-30
Blue Cross/Blue Shield Massachusetts reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2009-09-30. 39,000 Massachusetts residents were affected. The report records the breach type as electronic.
Supply-chain cascadesreviewed and confirmed
- Blue Cross and Blue Shield of Massachusetts, Inc.’s filing is one of at least 2 in the Cleo supply-chain incident (2025).