Blue Cross Blue Shield of Tennessee Settlement Landing Page
This is a landing page for the resolution agreement and corrective action plan to settle potential violations of the HIPAA Privacy and Security Rules by Blue Cross Blue Shield of Tennessee (BCBST).
Issued by: Office for Civil Rights (OCR)
HHS settles HIPAA case with BCBST for $1.5 million
On March 9, 2012, Blue Cross Blue Shield of Tennessee (BCBST) agreed to pay $1,500,000 to settle potential violations of the HIPAA Privacy and Security Rules. BCBST also agreed to a corrective action plan which includes: reviewing, revising, and maintaining its Privacy and Security policies and procedures; conducting regular and robust trainings for all BCBST employees covering employee responsibilities under HIPAA; and performing monitor reviews to ensure BCBST compliance with the plan. The investigation followed a notice submitted by BCBST to HHS in which it was reported that 57 unencrypted computer hard drives containing PHI of over 1 million individuals had been stolen from a leased facility in Tennessee. The enforcement action is the first resulting from a breach report required by the Health Information Technology for Economic and Clinical Health (HITECH) Act Breach Notification Rule.
- Read the Resolution Agreement and CAP - PDF
- For Information on OCR’s Enforcement Activities
- Read the HHS Press Release
- To File a Health Information Privacy or Security Complaint
HHS is committed to making its websites and documents accessible to the widest possible audience, including individuals with disabilities. We are in the process of retroactively making some documents accessible. If you need assistance accessing an accessible version of this document, please reach out to the firstname.lastname@example.org.
DISCLAIMER: The contents of this database lack the force and effect of law, except as authorized by law (including Medicare Advantage Rate Announcements and Advance Notices) or as specifically incorporated into a contract. The Department may not cite, use, or rely on any guidance that is not posted on the guidance repository, except to establish historical facts.