- State
- IN
- Covered entity type
- Business Associate
- Individuals affected
- 1,008
- Business associate present
- Yes
- Type of breach
- Other
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), City of Henderson, discovered that on several occasions between January 23, 2013, and March 3, 2013, its business associate (BA) broker, Keystone Insurers Group, disclosed more than the minimum necessary information to several health care providers who were being considered as a possible partner with the City in development of a City-run healthcare clinic. The BA had been hired to assist in the evaluation process of determining whether a City-operated health clinic would reduce health care costs. The types of protected health information (PHI) involved in the breach included demographic information such as names, insurance numbers, addresses, birthdates, and clinical information, such as diagnoses, treatment, prescriptions, and expenses. The CE provided breach notification to HHS, affected individuals, and the media, and posted substitute notice on its website. In response to the incident, the CE obtained certificates of deletion and destruction from the recipients of the PHI and it terminated its agreement with the BA. The CE also revised its request for proposals process to include information about potential brokers’ HIPAA training and any prior HIPAA breaches. In response to OCR’s investigation, the CE created and implemented privacy policies and procedures, and trained staff on its HIPAA policies.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.