DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

SimplyWell (Viverae) notifying Lincoln Electric System employees of of personal health info breach

Posted on May 24, 2018 by Dissent

It’s been a while since I’ve noticed a third-party breach of a wellness vendor, but here we go, it seems. SimplyWell (“Viverae”) works with Healthbreak, who provides wellness services to the firm in question. 

SimplyWell, Inc. (“SimplyWell”) recently discovered a data privacy incident that may affect the privacy of certain Lincoln Electric System (“LES”) employees’ personal health information. SimplyWell works with LES’ vendor, Healthbreak, Inc., for the provision of wellness services.

On Feb. 9, 2018, LES began a new wellness challenge that was added to the “Wellness Events” section of the SimplyWell-LES private portal. The page included a hyperlink that erroneously led to a file that contained a list of LES members who were tobacco-free as of Oct. 27, 2017. On March 23, 2018, LES discovered this information and notified SimplyWell of this erroneous link. The file was immediately deleted from the portal and SimplyWell commenced an investigation to confirm the nature and scope of this incident. The investigation determined the accessible information was limited to an employee’s name, gender, date of birth, SimplyWell identification number, and the employee’s status as a non-smoker. The investigation further determined that the portal for the wellness program could not be and was not accessed by anyone outside of LES, Healthbreak, or SimplyWell.   

SimplyWell takes the security of personal information in its care very seriously, and has determined that this potential breach was the result of human error at SimplyWell. SimplyWell has the technical security controls, system safeguards, policies, and processes in place in order to protect the information to which SimplyWell has access. SimplyWell provided written notice of this incident to those individuals whose information was present in the inadvertently posted file. While the information present in the inadvertently posted file was limited, SimplyWell is reminding potentially affected individuals to remain vigilant for suspicious activity.

Potentially impacted individuals may also find information regarding identity theft, fraud alerts, security freezes, and the steps they may take to protect their information by contacting the credit bureaus, the Federal Trade Commission, or their state Attorney General. The Federal Trade Commission can be reached at: 600 Pennsylvania Avenue NW, Washington, D.C. 20580; www.identitytheft.gov; 1-877-ID-THEFT (1-877-438-4338); and TTY: 1-866-653-4261. Additional information on obtaining a free credit report annually from each of the three major credit reporting bureaus can be found by visiting www.annualcreditreport.com, calling 877-322-8228, or contacting the three major credit bureaus directly at:

  • Equifax, P.O. Box 105069, Atlanta, GA 30348, 800-525-6285, www.equifax.com
  • Experian, P.O. Box 2002, Allen, TX 75013, 888-397-3742, www.experian.com
  • TransUnion, P.O. Box 2000, Chester, PA 19016, 800-680-7289, www.transunion.com

SimplyWell sincerely regrets any inconvenience this incident may have caused. The safety and security of all member information is a top priority for SimplyWell and Healthbreak. If individuals have any questions or would like additional information regarding this incident, they are asked to contact the SimplyWell Customer Care number at 1-877-991-9355 (and select option #7).

About SimplyWell
SimplyWell (known publicly by former company name, Viverae®, will rebrand under its legal name, SimplyWell, in November 2018) is a workplace wellness technology company based in Dallas, Texas. Rooted in care and focused on reducing health risks, our innovative application empowers employers to create cultures of health and well-being.

SimplyWell’s workplace wellness programs are compliant with Affordable Care Act requirements and applicable law, and National Committee for Quality Assurance and national health advocacy group standards.

SOURCE SimplyWell, Inc.


Related:

  • Protected health information of 462,000 members of Blue Cross Blue Shield of Montana involved in Conduent data breach
  • Resource: NY DFS Issues New Cybersecurity Guidance to Address Risks Associated with the Use of Third-Party Service Providers
  • TX: Kaufman County Faces Cybersecurity Attack: Courthouse Computer Operations Disrupted
  • Attorney General James Announces Settlement with Wojeski & Company Accounting Firm
  • JFL Lost Up to $800,000 Weekly After Cyberattack, CEO Says No Patient or Staff Data Was Compromised
  • Before Their Telegram Channel Was Banned Again, ScatteredLAPSUS$Hunters Dropped Files Doxing Government Employees (2)
Category: ExposureHealth DataSubcontractorU.S.

Post navigation

← Another data breach for South Africa – 934,000 passwords and IDs exposed
Coca-Cola notifying employees of insider breach (updated) →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Suspected Russian hacker reportedly detained in Thailand, faces possible US extradition
  • Did you hear the one about the ransom victim who made a ransom installment payment after they were told that it wouldn’t be accepted?
  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Almost two years later, Alpha Omega Winery notifies those affected by a data breach.
  • Court of Appeal reaffirms MFSA liability in data leak case, orders regulator to shoulder costs

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Lawmakers Warn Governors About Sharing Drivers’ Data with Federal Government
  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.