DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Yet another mailing error from Blue Cross Blue Shield of Florida?

Posted on June 30, 2011 by Dissent

Oops! It seems I missed another Blue Cross Blue Shield mailing error data breach. It’s understandable, I suppose, since there have been a bunch of Blue Cross breaches in the past few months, but thanks to the good folks at ITRC for alerting me to the omission.

Here’s Blue Cross Blue Shield of Florida’s statement about the breach:

JACKSONVILLE, Fla., June 17, 2011 /PRNewswire/ — In April 2011, Blue Cross and Blue Shield of Florida (BCBSF) discovered that, because of a manual error, it had inadvertently mailed some member health statements to incorrect prior addresses. BCBSF fixed the issue immediately.  BCBSF has evaluated its processes and made the appropriate changes to prevent this error from reoccurring.  Impacted members have been contacted.  No social security numbers, date of birth or other financial information were included on the information sent to the incorrect prior addresses.

Less than 3,500 members (out of nearly 4 million members) were impacted by this one mailing. All other mailings of member information were mailed to the current address on file with the company.

BCBSF has established a dedicated customer service line for impacted members to call if they have any questions about this matter or would like to update their address. The toll free number is 877-526-1013.

About Blue Cross and Blue Shield of Florida:

Blue Cross and Blue Shield of Florida is a leader in Florida’s health industry. Since 1944, the company has been dedicated to meeting the diverse needs of all those it serves by offering an array of choices. BCBSF is a not-for-profit, policyholder-owned, tax-paying mutual company. Headquartered in Jacksonville, Fla., BCBSF is an independent licensee of the Blue Cross and Blue Shield Association, an association of independent Blue Cross and Blue Shield companies. For more information concerning BCBSF, please visit its website at www.bcbsfl.com.

SOURCE Blue Cross and Blue Shield of Florida

According to  Joe Goedert on Health Data Management:

Information in the documents sent to wrong addresses included member name, insurance number, diagnoses codes and descriptions, procedure code and description, prescription name and provider name. No Social Security numbers, financial information or dates of birth were included. The plan currently is not offering credit or identity theft protection services.

In other mail-related data breaches this year:

  • Anthem Blue Cross issued a statement concerning the 37,900 mailings that went out to Medicare Supplement members with their names, addresses, zip codes, and their Social Security Numbers written next to the words “PRIORITY CODE.”
  • Blue Cross and Blue Shield of Florida issued a statement apologizing that 7,400 members’ explanation of benefits statements were sent to their old addresses in January.

Hey, wait a minute: isn’t the newest breach from this month exactly the same kind of problem that they had in January? At the time, they wrote:

In late January 2011, Blue Cross and Blue Shield of Florida (BCBSF) discovered that, because of a system error, it had inadvertently mailed some member health information to incorrect addresses. BCBSF regrets that this error occurred. BCBSF fixed the issue the same day it was discovered and current addresses are now in place for all of these members. BCBSF has evaluated its systems and made the appropriate changes to prevent this error from reoccurring.

Oh, I see: the problem in January was a system error. The problem in April was a manual error. Whew – I was afraid that they hadn’t really addressed the problem in January, but if it was a manual error, well, then, this will never happen again…. we hope.

  • Also in January, Blue Cross Blue Shield of Michigan apologized to 6,500 members whose personal, but non-medical information was exposed on a third-party vendor’s web site.

Related:

  • JFL Lost Up to $800,000 Weekly After Cyberattack, CEO Says No Patient or Staff Data Was Compromised
  • Massachusetts hospitals Heywood, Athol say outage was a cybersecurity incident
  • Heritage Provider Network $49.99M Class Action Settlement
  • Integris Health Agrees to $30 Million Settlement Over 2023 Data Breach
  • They were victims of a massive data breach in 2009. Interior Health denied it for a decade.
  • Watsonville Community Hospital had a data breach -- or two. It would be helpful to know which.
Category: Health Data

Post navigation

← Canadian data breach causes Durham residents to 'not be another victim'
TN: Laptop with more than 1,500 patients’ data stolen →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Washington Post hack exposes personal data of John Bolton, almost 10,000 others
  • Draft UK Cyber Security and Resilience Bill Enters UK Parliament
  • Suspected Russian hacker reportedly detained in Thailand, faces possible US extradition
  • Did you hear the one about the ransom victim who made a ransom installment payment after they were told that it wouldn’t be accepted?
  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Maryland Privacy Crackdown Raises Bar for Disclosure Compliance
  • Lawmakers Warn Governors About Sharing Drivers’ Data with Federal Government
  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.