- State
- IN
- Covered entity type
- Health Plan
- Individuals affected
- 9,305
- Business associate present
- Yes
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Golden Rule Insurance Company, the covered entity (CE), reported that its business associate (BA), experienced an impermissible breach of protected health information (PHI) when it left its web-based storage system unsecured. This breach incident affected 9,305 individuals. The PHI involved included names, addresses, dates of birth, Social Security numbers, financial information, and clinical information. The CE notified HHS, affected individuals, the media, and provided affected individuals with one year of credit and identity theft monitoring services. Additionally, the CE terminated its relationship with the BA. The CE provided affected individuals with a toll-free phone number for questions or concerns.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.