A benefits staff member at JHU/APL Medical and Dental Insurance Plan accidentally attached a file containing PHI to an email sent to 85 employees. The email included names, dates of birth, Social Security numbers, and marital and disability status of approximately 692 individuals. All recipients were notified within 5 days and the email was deleted. Following an OCR investigation, the covered entity updated policies requiring peer review of bulk benefit emails, mandated PHI email encryption, took personnel action against the responsible employee, and committed to additional HIPAA and encryption training. Location of breached information: Other.
Affected (this filing): 692