Back to the register

State of Tennessee State Insurance Plan

ArchivedSubmitted 08/15/2014
State
TN
Covered entity type
Health Plan
Individuals affected
60,582
Business associate present
No
Type of breach
Hacking/IT Incident
Location of breached information
Network Server
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

The covered entity (CE), State of Tennessee State Insurance Plan, discovered on June 10, 2014, that Onsite Health Diagnostics, a subcontractor of its business associate (BA) American Healthways Services, experienced a security incident in which an unknown source gained unauthorized access to its online scheduler during the period from January 4, 2014 to April 11, 2014. The incident resulted in unauthorized access to an information table containing names, dates of birth, addresses, email addresses, phone numbers, and genders of 60,582 individuals. The CE had a BA agreement in place with the BA. The CE provided breach notification to HHS and demanded that the BA submit a corrective action plan to make sure the problem that led to the breach had been remediated. The subcontractor provided breach notification to HHS, sent individual notification, and provided media notice. The subcontractor offered identity protection to the affected individuals and transitioned customers to an improved scheduling system. OCR obtained assurances from the CE that the CE, BA, and subcontractor implemented the corrective actions noted above.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.