CareFirst Blue Cross Blue Shield
ent_ffe031c000d6b4ccb5652e69
Disclosures
5
State AG · HHS OCR · 3 jurisdictions
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
6,200
as filed · HHS OCR MD
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CareFirst Blue Cross Blue Shield
- Normalized
- carefirst blue cross blue shield— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- carefirst.com
Disclosure history (5)newest first
- 🦀Maryland State AGas victim2025-03-19
CareFirst BlueCross BlueShield notified the Maryland AG of a misdelivery incident on March 19, 2025. On Feb 3, 2025, an employee erroneously attached one member's PHI (name, DOB, ID, health record, medication) to another member's appeal letter. One Maryland resident was impacted. CareFirst offered 2 years of Experian IdentityWorks and retrained the employee.
- 🦀Maryland State AGas victim2025-03-05
CareFirst BlueCross BlueShield notified the Maryland Attorney General on March 5, 2025, regarding a data incident involving five Maryland residents. An employee of vendor Fiserv mistakenly changed a printing machine setting, causing member ID cards containing names, addresses, and member IDs to be double-stuffed and mailed to another member. The error was discovered on January 6, 2025, and investigation concluded on January 30, 2025. No evidence of misuse was found. CareFirst offered two years of free credit monitoring via Experian IdentityWorks.
- DCHHS OCRas victim2024-02-16
CareFirst BlueCross BlueShield Community Health Plan – District of Columbia reported to HHS on 2024-02-16 an Unauthorized Access/Disclosure affecting 2,189 individuals. An employee inadvertently made PHI viewable via the Internet from a Network Server. PHI involved included names, addresses, dates of birth, claims information, diagnoses, conditions, and other treatment details. The entity notified HHS, affected individuals, and the media, and implemented enhanced encryption, stronger passwords, and additional technical safeguards.
- MARYLANDHHS OCRas victim2018-04-26
CareFirst Blue Cross Blue Shield (MD) reported to HHS on 2018-04-26 a Hacking/IT Incident affecting 6,200 individuals. An employee was the victim of an email phishing attack that exposed ePHI including names, dates of birth, Social Security numbers, and health insurance information. Breached information was located in Email. The CE notified HHS and affected individuals, implemented additional technical safeguards, and retrained staff on recognizing fraudulent emails. OCR obtained assurances of corrective action.
- 🐻California State AGas victim2015-05-20
CareFirst BlueCross Blueshield reported a data breach to the California Attorney General. The filing lists the date of breach as June 19, 2014. The attached consumer notification letter is empty in the provided source, so specific details regarding the nature of the breach, data types affected, and number of individuals impacted are not available for extraction.