CareFirst Blue Cross Blue Shield
ent_ffe031c000d6b4ccb5652e69
Disclosures
7
State AG · HHS OCR · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
1,300,000
nationwide · HHS OCR MD
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CareFirst Blue Cross Blue Shield
- Normalized
- carefirst blue cross blue shield— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- carefirst.com
Disclosure history (7)newest first
- Maryland State AGas victim2025-03-19
CareFirst BlueCross BlueShield notified the Maryland AG of a misdelivery incident on March 19, 2025. On Feb 3, 2025, an employee erroneously attached one member's PHI (name, DOB, ID, health record, medication) to another member's appeal letter. One Maryland resident was impacted. CareFirst offered 2 years of Experian IdentityWorks and retrained the employee.
- Maryland State AGas victim2025-03-05
CareFirst BlueCross BlueShield notified the Maryland Attorney General on March 5, 2025, regarding a data incident involving five Maryland residents. An employee of vendor Fiserv mistakenly changed a printing machine setting, causing member ID cards containing names, addresses, and member IDs to be double-stuffed and mailed to another member. The error was discovered on January 6, 2025, and investigation concluded on January 30, 2025. No evidence of misuse was found. CareFirst offered two years of free credit monitoring via Experian IdentityWorks.
- DISTRICT OF COLUMBIAHHS OCRas reporting2024-02-16
CareFirst BlueCross BlueShield Community Health Plan – District of Columbia reported to HHS on 2024-02-16 an Unauthorized Access/Disclosure affecting 2,189 individuals. An employee inadvertently made PHI viewable via the Internet from a Network Server. PHI involved included names, addresses, dates of birth, claims information, diagnoses, conditions, and other treatment details. The entity notified HHS, affected individuals, and the media, and implemented enhanced encryption, stronger passwords, and additional technical safeguards.
- MARYLANDHHS OCRas victim2018-04-26
CareFirst Blue Cross Blue Shield (MD) reported to HHS on 2018-04-26 a Hacking/IT Incident affecting 6,200 individuals. An employee was the victim of an email phishing attack that exposed ePHI including names, dates of birth, Social Security numbers, and health insurance information. Breached information was located in Email. The CE notified HHS and affected individuals, implemented additional technical safeguards, and retrained staff on recognizing fraudulent emails. OCR obtained assurances of corrective action.
- MARYLANDHHS OCRas victim2015-05-20
CareFirst Blue Cross Blue Shield reported to HHS on 2015-05-20 a Hacking/IT Incident affecting 1300000 individuals. Breached information located on Network Server. The ePHI involved included names, health insurance information, usernames, email addresses, and dates of birth.
- New Hampshire State AGas victim2015-05-20
CareFirst BlueCross BlueShield notified the NH AG of a cyberattack discovered April 21, 2015, involving unauthorized access to a broker database on June 19, 2014. Attackers potentially acquired broker names, SSNs, and usernames. 1.1 million individuals affected nationwide; 7 NH residents. No passwords or financial/medical data accessed. Credit monitoring offered.
- California State AGas victim2015-05-20
CareFirst BlueCross Blueshield reported a data breach to the California Attorney General. The filing lists the date of breach as June 19, 2014. The attached consumer notification letter is empty in the provided source, so specific details regarding the nature of the breach, data types affected, and number of individuals impacted are not available for extraction.