- State
- AL
- Covered entity type
- Health Plan
- Individuals affected
- 1,349
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), Public Education Employees’ Health Insurance Plan, discovered that as a result of an information technology (IT) upgrade some documents that included protected health information (PHI) related to multiple members inadvertently became viewable to other members through its Member Online System (MOS). The PHI involved in the breach included members’ and dependents’ names, program identification numbers, birth dates, and retirement dates pertaining to 1,349 individuals. Some of the document also contained social security numbers. The CE provided breach notification to HHS, affected individuals, and the media. The CE provided credit monitoring services to all affected individuals for 12 months at no cost to them. In response to the breach, the CE investigated and worked in conjunction with Deloitte (the company hired to provide software and professional services for the new IT system) to revise the newly implemented software coding to terminate access to the documents involved in this incident. The CE and Deloitte were able to apply an emergency fix on the same day that the incident was discovered. Additionally, the CE revised its internal protocols for uploading documents. OCR obtained assurances that the CE implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.