CarePlus Notifies 11,200 Health Plan Members of PHI Breach

by | Feb 7, 2018

Florida-based CarePlus Health Plans has experienced a PHI breach incident which has seen certain plan members’ protected health information disclosed, in error, to other plan subscribers.

A mailing including ‘Explanation of benefits statements (EOB)’ was sent to plan members between January 9 and January 16, 2018, although on January 17, Miami-based CarePlus discovered that a number of the statements had been sent to the wrong people.

The EoB statements listed names, addresses, dates of service, providers of services, the services that had been given, CarePlus identification numbers and CarePlus health plan titles. Highly sensitive data such as Social Security numbers and financial details were not listed on the EoB statements. CarePlus has not been in receipt any reports to suggest any of the disclosed information has been improperly used.

The incorrect mailing incident has been looked into by CarePlus and action has been taken to avoid any similar privacy incidents from being incurred going forward. CarePlus says the incorrect mailing incident was due to a number of programming and printing errors. Breach notification letters are now being broadcast to all people impacted by the breach to make them aware of the accidental sharing of their private health information.

The incorrect mailing incident has not been posted on the Department of Health and Human Services’ Office for Civil Rights (OCR) data breach portal, although WFLA has remarked that incident could have exposed almost 11,200 plan members.

This is the second incorrect mailing incident experienced by CarePlus Health Plans in the past three years. In September 2015, CarePlus revealed more than 1,400 of its plan subscribers had been exposed in an incorrect mailing incident that included two EoB statements accidentally inserted into the wrong envelopes – The correct EoB statement and the statement of another CarePlus plan subscriber.

Raise the level of HIPAA Awareness in your organization with Learner-Friendly, Comprehensive and Affordable HIPAA Training.

COMPREHENSIVE HIPAA TRAINING

Ryan Coyne

Ryan Coyne is a results-driven leader in the healthcare compliance industry, specializing in regulatory compliance, compliance training, and assisting healthcare organizations and business associates in achieving and maintaining compliance. With a deep knowledge of healthcare regulations and a keen understanding of the challenges faced by the industry, Ryan has developed a reputation as a trusted advisor and advocate for ethical and compliant practices in healthcare. Ryan has successfully advised and guided numerous healthcare organizations, business associates, and healthcare professionals on achieving and maintaining compliance with regulatory training requirements. Ryan's professional focus is using his in-depth expertise and leading a world class team of subject matter experts at ComplianceJunction in regulatory compliance to help organisations navigate the complex landscape of ensuring staff adhere to healthcare regulations. You can connect with Ryan via LinkedIn and follow on Twitter

Raise the level of HIPAA Awareness in your organization with Learner-Friendly, Comprehensive and Affordable HIPAA Training.

Comprehensive HIPAA Training

Used in 1000+ Healthcare Organizations and 100+ Universities

    Full Course - Immediate Access

    Privacy Policy