- State
- ID
- Covered entity type
- Health Plan
- Individuals affected
- 4,824
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), a group health plan, reported to OCR that multiple employees responded to a phishing email which compromised the protected health information (PHI) of 4,824 plan members. The types of breached PHI included names, addresses, dates of birth, driver’s license information, social security numbers, claims information, diagnoses, and medications. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE strengthened its administrative and technical safeguards, such as authentication procedures and measures to identify and remove malicious emails. It also increased its security training. As a result of OCR’s investigation the CE enhanced its practices for safeguarding PHI.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.