Envision Rx HIPAA breach update

I am writing to provide an update on the incident involving a number of OU Health Plan members.

As you may know, Envision Rx discovered the issue on October 5, 2015 upon receiving notice from our office that some Plan members reported receiving letters containing other member’s prescription drug information.

Upon our notifying Envision Rx, they began immediately investigating the occurrence. Their initial findings indicate that data did not export correctly for the ADOBE Portable Document Format (PDF) file from their source data which was verified as accurate.  This PDF file was then used to populate the mailing which resulted in approximately 540 member’s letters containing other member’s claims information. The complete mailing was over 11,000 letters, so that approximately 5% were corrupted. The information included other member’s first and last name, date of service, name of drug and dosage, cost of prescription, member copay, and Plan paid amount.  The information did not include the other member’s demographic, financial information or Social Security Numbers.

They are continuing to investigate this incident to be certain that they have identified all data inaccuracies, the definitive number of affected members and the root cause of the error.

The following are the steps Envision Rx is taking in accordance with potential Health Insurance Portability and Accountability Act (HIPAA) violations. This is legislationthat was passed by Congress in 1996and is enforced by the Federal Government’s Department of Health and Human Services (HHS):

  • It is essential that Envision accurately identify the affected individuals so that they can provide timely breach notification to effected members.  Therefore, they continue to investigate, analyze the data, and conduct quality assurance to ensure the accuracy of their findings.
  • Envision will mail the breach notifications to each individual whose information was contained in another member’s letter.
  • Envision will send members who received other members’ information a letter explaining our error and requesting they return the “wrong” information to Envision in the self-addressed stamped envelope provided.  Envision will  resend the correct information to this group of individuals.
  • HIPAA requires that breaches affecting 500 or more individuals be reported to the Secretary of the Department of Health and Human Services.  Envision will report accordingly.
  • HIPAA requires that breaches affecting over 500 individuals be reported to a prominent media outlet serving the state or jurisdiction of the affected individuals.  Envision will report accordingly.
  • Envision is analyzing reporting obligations under state law and will report accordingly.
  • Envision will implement whatever steps are necessary to mitigate and prevent future occurrences.

Any additional information that is received regarding this incident will be communicated as quickly as possible.

Latest News

The OU Health Plan has arranged with EmpiRx to offer the flu vaccine to Plan members for a $0 copay

To receive your FREE Flu Vaccine, COVID-19 vaccination or COVID-19 booster shot simply go to any participating pharmacy and present your OU Health member ID card.


To receive your Free Flu Vaccine or COVID-19 vaccine or booster shot, simply go to any pharmacy that participates with the CVS Caremark/ Silver Script network of pharmacies and present your Silver Script Prescription ID card.

Note to all members: This year, please consider obtaining the flu shot in October, before the flu season starts, as medical experts have advised co-exposure to both COVID-19 and the flu could result in serious illness such as pneumonia and respiratory distress, hospitalization or even death. This is possible because the flu and COVID-19 are caused by different viruses.

***OU Health announces EmpiRx Health as the new Pharmacy Benefits Manager effective July 1, 2021***

Click below to view this presentation:

If you can't view the image above, copy and paste this URL into your browser:
Click Here


The Orange Ulster School Districts Health Plan will provide 100% coverage for in-network diagnosing and laboratory testing for the potential Corona Virus office visit or Live Health Online (Telemed) visit. Click here to download

Friday,March 8 2021

With 2021 around the corner, the Orange Ulster School Districts Health Plan is excited to announce several Plan benefit Read More

read more news