A case involved a national health maintenance organization sending an explanation of benefits (EOB) to a complainant’s unauthorized family member by mail.
OCR investigated the case and concluded that a flaw in the system had caused the event to happen and had put the health information of approximately 2,000 families at risk of disclosure in violation of the Security Rule.
The insurer was required to correct the flaw in its computer system within six months.