Health Insurer Pays $5.1 Million to Settle Data Breach Affecting Over 9.3 Million People

The Lifetime Healthcare Companies, including its affiliates Excellus Health Plan, Inc. doing business as Excellus BlueCross BlueShield and Univera Healthcare, Lifetime Health Medical Group, Lifetime Benefit Solutions, Lifetime Care, and The MedAmerica Companies (collectively "Excellus Health Plan") have agreed to pay $5.1 million to the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) and to implement a corrective action plan to settle potential violations of the Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security Rules related to a breach affecting over 9.3 million people. Excellus Health Plan is a New York state health services corporation that provides health insurance coverage to over 1.5 million people in Upstate and Western New York.

* People using assistive technology may not be able to fully access information in this file. For assistance, contact the HHS Office for Civil Rights at (800) 368-1019, TDD toll-free: (800) 537-7697, or by emailing [email protected].

Content created by Office for Civil Rights (OCR)
Content last reviewed on January 15, 2021