- State
- IA
- Covered entity type
- Health Plan
- Individuals affected
- 862
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Paper/Films
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On August 5, 2015, the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR), Midwest Region initiated a review of the covered entity (CE), Iowa Department of Human Services. This review stems from a complaint and security breaches that the CE self-reported to OCR-HQ (as required by 45 CFR § 164.408(b)), which occurred over a period of nine years from 2005 to 2014. The CE provided breach notification to HHS, affected individuals, and the media. To prevent similar breaches from happening in the future, the CE conducted multiple internal investigations, evidenced the performance of its risk analysis and corresponding risk management plan. It also sanctioned the employees involved in the breach incidents, provided training to its staff on its policies and procedures regarding Security Awareness. Additionally, the CE implemented annual security control reviews that assess its compliance with the Privacy, Security, and Breach Notification Rules and implemented new HIPAA policies and procedures. OCR obtained copies of the CE's executed business associate agreements and documentation that substantiates the CE's corrective actions described above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.