- State
- WA
- Covered entity type
- Health Plan
- Individuals affected
- 381,504
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server, Other
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Transactions Application Group, Inc., a business associate (BA) for the covered entity (CE), Community Health Plan of Washington, failed to properly secure a port on a computer network server used for transferring electronic files (a File Transfer Protocol (FTP) server), resulting in an incident of unauthorized access to electronic protected health information (ePHI) maintained at the BA. The breach affected 381,504 individuals and included individuals’ names, addresses, dates of birth, social security numbers, and certain coding information related to health care claims. The CE provided breach notification to the affected parties, the media, and HHS, and offered one year of free credit and identity theft monitoring. The CE also implemented additional technical safeguards. OCR obtained assurances that the CE implemented the corrective actions listed above .
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.