- State
- IN
- Covered entity type
- Health Plan
- Individuals affected
- 710
- Business associate present
- Yes
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Other
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On January 10, 2017, Shiel Sexton learned that its former business associate (BA), HCH Administration, Inc., had disclosed protected health information (PHI) in 2012 to a reinsurer beyond the minimum necessary requirements in the business associate agreement (BAA) with Shiel Sexton. The breach affected 710 individuals and the types of PHI involved included names and social security numbers. The covered entity (CE) provided breach notification to affected individuals and the media on January 27, 2017, and also notified HHS. OCR obtained documented assurances that the CE implemented these corrective action steps. During the course of this investigation, OCR learned that the BA dissolved its business in 2013.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.