Blue Shield of California inadvertently included provider Social Security numbers (SSNs) in public provider rosters submitted to the California Department of Managed Health Care (DMHC) in early 2013. The DMHC discovered the error in May 2014 and found that the rosters, containing names, addresses, and SSNs, had been released in response to ten Public Records Act requests. Blue Shield and the DMHC implemented data loss prevention software and revised submission procedures to prevent recurrence. Affected providers were offered one year of Experian's ProtectMyID identity protection service.