On April 23, 2018, BioIQ, Inc., a business associate, sent a mass email to members of TML Multistate Intergovernmental Employee Benefits Pool containing incorrect member names in the salutations, exposing the first and last names of 4,059 individuals. The breach was reported to HHS on May 25, 2018. Upon discovery, the BA retrained the responsible employee, updated email workflow procedures to include QA review, and received OCR technical assistance on its risk analysis and risk management plan. Breached information located on Email.
Affected (this filing): 4,059