DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

SimplyWell (Viverae) notifying Lincoln Electric System employees of of personal health info breach

Posted on May 24, 2018 by Dissent

It’s been a while since I’ve noticed a third-party breach of a wellness vendor, but here we go, it seems. SimplyWell (“Viverae”) works with Healthbreak, who provides wellness services to the firm in question. 

SimplyWell, Inc. (“SimplyWell”) recently discovered a data privacy incident that may affect the privacy of certain Lincoln Electric System (“LES”) employees’ personal health information. SimplyWell works with LES’ vendor, Healthbreak, Inc., for the provision of wellness services.

On Feb. 9, 2018, LES began a new wellness challenge that was added to the “Wellness Events” section of the SimplyWell-LES private portal. The page included a hyperlink that erroneously led to a file that contained a list of LES members who were tobacco-free as of Oct. 27, 2017. On March 23, 2018, LES discovered this information and notified SimplyWell of this erroneous link. The file was immediately deleted from the portal and SimplyWell commenced an investigation to confirm the nature and scope of this incident. The investigation determined the accessible information was limited to an employee’s name, gender, date of birth, SimplyWell identification number, and the employee’s status as a non-smoker. The investigation further determined that the portal for the wellness program could not be and was not accessed by anyone outside of LES, Healthbreak, or SimplyWell.   

SimplyWell takes the security of personal information in its care very seriously, and has determined that this potential breach was the result of human error at SimplyWell. SimplyWell has the technical security controls, system safeguards, policies, and processes in place in order to protect the information to which SimplyWell has access. SimplyWell provided written notice of this incident to those individuals whose information was present in the inadvertently posted file. While the information present in the inadvertently posted file was limited, SimplyWell is reminding potentially affected individuals to remain vigilant for suspicious activity.

Potentially impacted individuals may also find information regarding identity theft, fraud alerts, security freezes, and the steps they may take to protect their information by contacting the credit bureaus, the Federal Trade Commission, or their state Attorney General. The Federal Trade Commission can be reached at: 600 Pennsylvania Avenue NW, Washington, D.C. 20580; www.identitytheft.gov; 1-877-ID-THEFT (1-877-438-4338); and TTY: 1-866-653-4261. Additional information on obtaining a free credit report annually from each of the three major credit reporting bureaus can be found by visiting www.annualcreditreport.com, calling 877-322-8228, or contacting the three major credit bureaus directly at:

  • Equifax, P.O. Box 105069, Atlanta, GA 30348, 800-525-6285, www.equifax.com
  • Experian, P.O. Box 2002, Allen, TX 75013, 888-397-3742, www.experian.com
  • TransUnion, P.O. Box 2000, Chester, PA 19016, 800-680-7289, www.transunion.com

SimplyWell sincerely regrets any inconvenience this incident may have caused. The safety and security of all member information is a top priority for SimplyWell and Healthbreak. If individuals have any questions or would like additional information regarding this incident, they are asked to contact the SimplyWell Customer Care number at 1-877-991-9355 (and select option #7).

About SimplyWell
SimplyWell (known publicly by former company name, Viverae®, will rebrand under its legal name, SimplyWell, in November 2018) is a workplace wellness technology company based in Dallas, Texas. Rooted in care and focused on reducing health risks, our innovative application empowers employers to create cultures of health and well-being.

SimplyWell’s workplace wellness programs are compliant with Affordable Care Act requirements and applicable law, and National Committee for Quality Assurance and national health advocacy group standards.

SOURCE SimplyWell, Inc.


Related:

  • Protected health information of 462,000 members of Blue Cross Blue Shield of Montana involved in Conduent data breach
  • Resource: NY DFS Issues New Cybersecurity Guidance to Address Risks Associated with the Use of Third-Party Service Providers
  • TX: Kaufman County Faces Cybersecurity Attack: Courthouse Computer Operations Disrupted
  • Attorney General James Announces Settlement with Wojeski & Company Accounting Firm
  • JFL Lost Up to $800,000 Weekly After Cyberattack, CEO Says No Patient or Staff Data Was Compromised
  • Before Their Telegram Channel Was Banned Again, ScatteredLAPSUS$Hunters Dropped Files Doxing Government Employees (2)
Category: ExposureHealth DataSubcontractorU.S.

Post navigation

← Another data breach for South Africa – 934,000 passwords and IDs exposed
Coca-Cola notifying employees of insider breach (updated) →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Fired techie admits sabotaging ex-employer, causing $862K in damage
  • Threat actors have reportedly launched yet another campaign involving an application connected to Salesforce
  • Russian hackers target IVF clinics across UK used by thousands of couples
  • US, allies sanction Russian bulletproof hosting services for ransomware support
  • Researchers claim ‘largest leak ever’ after uncovering WhatsApp enumeration flaw
  • Large medical lab in South Africa suffers multiple data breaches
  • Report released on PowerSchool cyber attack
  • Sue The Hackers – Google Sues Over Phishing as a Service
  • Princeton University Data Breach Impacts Alumni, Students, Employees
  • Eurofiber admits crooks swiped data from French unit after cyberattack

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Cole v. Quest Diagnostics: The Third Circuit Weighs in on Pixels, Privacy, and Medical Data
  • Closing the Privacy Gap: HIPRA Targets Health Apps and Wearables
  • Researchers claim ‘largest leak ever’ after uncovering WhatsApp enumeration flaw
  • CIPL Publishes Discussion Paper Comparing U.S. State Privacy Law Definitions of Personal Data and Sensitive Data
  • India’s Digital Personal Data Protection Act 2023 brought into force

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.