DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

SAMBA Federal Employee Benefit Association programming error resulted in mismailed information

Posted on March 23, 2018 by Dissent

From their press release:

SAMBA Federal Employee Benefit Association (“SAMBA”) recently learned of an incident that may affect information related to eligible family members of subscribers (“family members”) covered by the SAMBA Federal Employees Health Benefits Plan in 2017.

“We take this incident, and member privacy, very seriously,” Walter E. Wilson, SAMBA’s Executive Director stated. “We are taking steps to prevent any future data incident, and as always will continue to review and improve our processes, policies, and procedures that address data privacy,” he said.

What Happened

The Internal Revenue Service requires SAMBA to send its plan subscribers a notice known as a Form 1095-B that will support the subscribers’ and his or her covered family members’ compliance with the Affordable Care Act’s individual mandate, which remains in effect through 2018.  On February 19, 2018, SAMBA began the process of mailing out Form 1095-B notices to plan subscribers for the 2017 tax year.  During the mailing preparation process, a programming error occurred whereby some subscribers received a Form 1095-B containing the name and Social Security number for one or more family members of another plan subscriber.  All subscribers received a Form 1095-B that was erroneously dated 2016.  SAMBA became aware of the issue on or around February 22, 2018.  SAMBA corrected the programming error and mailed corrected 2017 Form 1095-B notices to all subscribers.  The incorrect 2016 Form 1095-B notices were not submitted to the Internal Revenue Service.

This incident did not disclose any subscriber’s Social Security number.

Information Affected

While SAMBA currently has no evidence that the impacted family members’ information was subject to any actual or attempted misuse, SAMBA confirmed that in some cases Form 1095-Bs containing family members’ names, Social Security numbers, and periods of health insurance coverage during the 2017 tax year were mailed to the incorrect subscriber.  SAMBA has written to the subscribers who received erroneous family member data. Those letters ask the subscriber to destroy the erroneous 2016 Form 1095-B.

Notification

SAMBA is mailing letters to impacted family members and is providing those family members with free credit monitoring and identity restoration services through AllClear ID.  SAMBA also informed the U.S. Department of Health and Human Services, certain state regulators and news media outlets about this incident, as required.

Fraud Prevention Tips

While SAMBA currently has no evidence that the impacted family members’ information was subject to any actual or attempted misuse, they encourage affected individuals to remain vigilant against incidents of identity theft and fraud, and to seek to protect against possible identity theft or other financial loss by regularly reviewing their financial account statements, credit reports, and explanations of benefits for suspicious activity.  Anyone with questions regarding how to best protect themselves from potential harm resulting from this incident, including how to receive a free copy of one’s credit report, and place a fraud alert or security freeze on one’s credit file, is encouraged to call our member support line at 1-855-220-9668 Monday through Saturday, 9:00 a.m. to 9:00 p.m. E.T.


Comments: Is it just me, or do these bold-faced (by me) statements sound contradictory:

During the mailing preparation process, a programming error occurred whereby some subscribers received a Form 1095-B containing the name and Social Security number for one or more family members of another plan subscriber.  All subscribers received a Form 1095-B that was erroneously dated 2016.  SAMBA became aware of the issue on or around February 22, 2018.  SAMBA corrected the programming error and mailed corrected 2017 Form 1095-B notices to all subscribers.  The incorrect 2016 Form 1095-B notices were not submitted to the Internal Revenue Service.

This incident did not disclose any subscriber’s Social Security number.

This incident was reported to HHS as affecting 13,942 members.

Category: ExposureHealth DataPaperU.S.

Post navigation

← Class action suit vs. CenturyLink and DirecTV alleges customer data can be accessed via internet search
Nine Iranians Charged With Conducting Massive Cyber Theft Campaign on Behalf of the Islamic Revolutionary Guard Corps →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Cyberattack pushes German napkin company into insolvency
  • WMATA Train Operators Arrested in Health Care Fraud Scheme
  • Washington Post investigating cyberattack on journalists, WSJ reports
  • Resource: State Data Breach Notification Laws – June 2025
  • WestJet investigates cyberattack disrupting internal systems
  • Plastic surgeons often store nude photos of patients with their identity information. When would we call that “negligent?”
  • India: Servers of two city hospitals hacked; police register FIR
  • Ph: Coop Hospital confirms probe into reported cyberattack
  • Slapped wrists for Financial Conduct Authority staff who emailed work data home
  • School Districts Unaware BoardDocs Software Published Their Private Files

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Vermont signs Kids Code into law, faces legal challenges
  • Data Categories and Surveillance Pricing: Ferguson’s Nuanced Approach to Privacy Innovation
  • Anne Wojcicki Wins Bidding for 23andMe
  • Would you — or wouldn’t you?
  • New York passes a bill to prevent AI-fueled disasters
  • Synthetic Data and the Illusion of Privacy: Legal Risks of Using De-Identified AI Training Sets
  • States sue to block the sale of genetic data collected by DNA testing company 23andMe

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.