- State
- WV
- Covered entity type
- Health Plan
- Individuals affected
- 1,400
- Business associate present
- Yes
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
By purporting to be healthcare providers, unauthorized users registered for a portal operated by Availity, a subcontractor of the covered entity’s (CE) business associate (BA), Humana, gaining access to protected health information (PHI) for a period of six months. The breach affected approximately 1,400 individuals, including the PHI of 39 members of this CE, such as names, insurance identification numbers, benefit information, and care reminders. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE obtained written assurances from Availity that it implemented technical safeguards to limit the risk of such incidents in the future, and obtained written assurances from the BA regarding the HIPAA compliance of its subcontractors. OCR reviewed the CE’s BA agreement and opened a separate investigation of the Humana breach involving the subcontractor.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.