HIPAA Journal is the leading provider of news, updates, and independent advice for HIPAA compliance

CarePlus Discovers Privacy Breach Affecting 1400

A potential privacy breach has been discovered to have affected CarePlus Health Plans. This is one of a number of patient privacy breaches to have been reported in recent weeks that have involved errors made when printing and mailing information to patients.

On September 18, 2015, CarePlus prepared a mailing of CarePlus Late Enrollment Penalty Premium Statements to patients. A machine was used to insert two premium statements into each envelope, but instead of inserting one statement, two were placed into each envelope by accident. The error resulted in 1,400 patients being sent statements intended for other patients.

The information potentially disclosed did not include highly sensitive information such as Social Security numbers, but patients have their names, addresses and CarePlus ID numbers accidentally disclosed to other health plan subscribers.

All affected members will undoubtedly already be aware of the error if they opened their statements, although they have now also been sent a HIPAA breach notification letter explaining the exposure of their information and how the incident occurred. They have also been issued with an apology for the error.

Please see the HIPAA Journal Privacy Policy

3 Steps To HIPAA Compliance

Please see HIPAA Journal
privacy policy

  • Step 1 : Download Checklist.
  • Step 2 : Review Your Business.
  • Step 3 : Get Compliant!

The HIPAA Journal compliance checklist provides the top priorities for your organization to become fully HIPAA compliant.

Given the limited amount of data disclosed it is unlikely that any patient will suffer damage or losses as a result of the privacy breach. CarePlus confirmed in a statement that it has not received any information to suggest that patient data have used inappropriately, although the company will continue to monitor all claims for any sign of fraudulent activity.

In order to prevent future breaches of this nature from occurring CarePlus is in the process of introducing new quality assurance procedures in its mailroom.

Spate of Mailing Errors Reported to the Office for Civil Rights


In August, Blue Cross and Blue Shield of North Carolina reported two privacy breaches resulting from printing and mailing errors that resulted in the PHI of members being accidentally disclosed to other individuals. One incident involved members’ information being printed on the reverse side of a document that was sent to other plan members, while a separate spreadsheet error similarly resulted in a mailing exposing patient data. In total, 2,300 members were affected by the two incidents.

Affinity Health Plan also suffered a similar incident in which double sided documents had different members’ information printed on each side.

The four incidents show how easy it is for privacy breaches to occur when printing and mailing letters to patients. HIPAA-covered entities should take note, and ensure that procedures are put in place in their mailrooms to double check for errors prior to letters being mailed. Vendors’ procedures should also be checked to make sure policies are in place to limit potential for patient and plan members’ privacy to be violated.

Author: Steve Alder is the editor-in-chief of HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered on HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has several years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics.