- State
- OK
- Covered entity type
- Health Plan
- Individuals affected
- 813
- Business associate present
- Yes
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Paper/Films
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), Oklahoma Department of Human Services, reported that it inadvertently issued client notice letters with a second, unrelated client’s name and address due to a software change, affecting 813 individuals. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE developed and deployed a solution that stopped incorrect information from being added to the notice letters provided to clients. OCR obtained assurances that the CE implemented the corrective action steps noted above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.