DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

SAMBA Federal Employee Benefit Association programming error resulted in mismailed information

Posted on March 23, 2018 by Dissent

From their press release:

SAMBA Federal Employee Benefit Association (“SAMBA”) recently learned of an incident that may affect information related to eligible family members of subscribers (“family members”) covered by the SAMBA Federal Employees Health Benefits Plan in 2017.

“We take this incident, and member privacy, very seriously,” Walter E. Wilson, SAMBA’s Executive Director stated. “We are taking steps to prevent any future data incident, and as always will continue to review and improve our processes, policies, and procedures that address data privacy,” he said.

What Happened

The Internal Revenue Service requires SAMBA to send its plan subscribers a notice known as a Form 1095-B that will support the subscribers’ and his or her covered family members’ compliance with the Affordable Care Act’s individual mandate, which remains in effect through 2018.  On February 19, 2018, SAMBA began the process of mailing out Form 1095-B notices to plan subscribers for the 2017 tax year.  During the mailing preparation process, a programming error occurred whereby some subscribers received a Form 1095-B containing the name and Social Security number for one or more family members of another plan subscriber.  All subscribers received a Form 1095-B that was erroneously dated 2016.  SAMBA became aware of the issue on or around February 22, 2018.  SAMBA corrected the programming error and mailed corrected 2017 Form 1095-B notices to all subscribers.  The incorrect 2016 Form 1095-B notices were not submitted to the Internal Revenue Service.

This incident did not disclose any subscriber’s Social Security number.

Information Affected

While SAMBA currently has no evidence that the impacted family members’ information was subject to any actual or attempted misuse, SAMBA confirmed that in some cases Form 1095-Bs containing family members’ names, Social Security numbers, and periods of health insurance coverage during the 2017 tax year were mailed to the incorrect subscriber.  SAMBA has written to the subscribers who received erroneous family member data. Those letters ask the subscriber to destroy the erroneous 2016 Form 1095-B.

Notification

SAMBA is mailing letters to impacted family members and is providing those family members with free credit monitoring and identity restoration services through AllClear ID.  SAMBA also informed the U.S. Department of Health and Human Services, certain state regulators and news media outlets about this incident, as required.

Fraud Prevention Tips

While SAMBA currently has no evidence that the impacted family members’ information was subject to any actual or attempted misuse, they encourage affected individuals to remain vigilant against incidents of identity theft and fraud, and to seek to protect against possible identity theft or other financial loss by regularly reviewing their financial account statements, credit reports, and explanations of benefits for suspicious activity.  Anyone with questions regarding how to best protect themselves from potential harm resulting from this incident, including how to receive a free copy of one’s credit report, and place a fraud alert or security freeze on one’s credit file, is encouraged to call our member support line at 1-855-220-9668 Monday through Saturday, 9:00 a.m. to 9:00 p.m. E.T.


Comments: Is it just me, or do these bold-faced (by me) statements sound contradictory:

During the mailing preparation process, a programming error occurred whereby some subscribers received a Form 1095-B containing the name and Social Security number for one or more family members of another plan subscriber.  All subscribers received a Form 1095-B that was erroneously dated 2016.  SAMBA became aware of the issue on or around February 22, 2018.  SAMBA corrected the programming error and mailed corrected 2017 Form 1095-B notices to all subscribers.  The incorrect 2016 Form 1095-B notices were not submitted to the Internal Revenue Service.

This incident did not disclose any subscriber’s Social Security number.

This incident was reported to HHS as affecting 13,942 members.

Category: ExposureHealth DataPaperU.S.

Post navigation

← Class action suit vs. CenturyLink and DirecTV alleges customer data can be accessed via internet search
Nine Iranians Charged With Conducting Massive Cyber Theft Campaign on Behalf of the Islamic Revolutionary Guard Corps →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • How the Signal Knockoff App TeleMessage Got Hacked in 20 Minutes
  • Cocospy stalkerware apps go offline after data breach
  • Ex-NSA bad-guy hunter listened to Scattered Spider’s fake help-desk calls: ‘Those guys are good’
  • Former Sussex Police officer facing trial for rape charged with 18 further offences relating to computer misuse
  • Beach mansion, Benz and Bitcoin worth $4.5m seized from League of Legends hacker Shane Stephen Duffy
  • Fresno County fell victim to $1.6M phishing scam in 2020. One suspected has been arrested, another has been indicted.
  • Ransomware Attack on ADP Partner Exposes Broadcom Employee Data
  • Anne Arundel ransomware attack compromised confidential health data, county says
  • Australian national known as “DR32” sentenced in U.S. federal court
  • Alabama Man Sentenced to 14 Months in Connection with Securities and Exchange Commission X Hack that Spiked Bitcoin Prices

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Police secretly monitored New Orleans with facial recognition cameras
  • Cocospy stalkerware apps go offline after data breach
  • Drugmaker Regeneron to acquire 23andMe out of bankruptcy
  • Massachusetts Senate Committee Approves Robust Comprehensive Privacy Law
  • Montana Becomes First State to Close the Law Enforcement Data Broker Loophole
  • Privacy enforcement under Andrew Ferguson’s FTC
  • “We would be less confidential than Google” – Proton threatens to quit Switzerland over new surveillance law

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.