On December 7, 2015, Blue Shield of California discovered that its network servers were breached via social engineering at its call centers in Costa Rica. The breach, submitted to HHS on January 14, 2016, affected 20,764 individuals. PHI exposed included names, addresses, dates of birth, and Social Security numbers. Remediation included disabling compromised credentials, redistributing new passwords, two-factor authentication for VPN access, and social engineering training for call center staff. OCR obtained assurances of corrective action.
Affected (this filing):