BeneSys, Inc. (MI), a business associate, reported to HHS on 2020-08-10 an Unauthorized Access/Disclosure affecting 1,070 individuals. An employee inadvertently emailed documents containing ePHI (names, Social Security numbers, and financial information) to the wrong recipient via email. The BA notified HHS and affected individuals, provided credit monitoring, sanctioned the responsible employee, implemented additional administrative safeguards, and retrained staff. OCR obtained assurances of corrective action.
Affected (this filing): 1,070