- State
- IA
- Covered entity type
- Business Associate
- Individuals affected
- 1,191
- Business associate present
- Yes
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Paper/Films
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Amerigroup Iowa, Inc., a business associate (BA) for the covered entity (CE), Iowa Department of Public Health, erroneously mailed letters to 1,191 of its minor members which contained the incorrect parent or guardian’s name. The type of protected health information (PHI) included in the breach included demographic and clinical information. The BA provided breach notification to affected individuals on behalf of the CE. Upon discovery of the breach incident on January 29, 2019, the BA investigated and determined that the incident resulted from a human error. Based on the breach, the BA sanctioned and retrained the responsible employee, revised its procedure for generating a member mailing list, and trained all workforce member on its updated procedure. OCR obtained assurances that the CE/BA implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.