- State
- MN
- Covered entity type
- Business Associate
- Individuals affected
- 1,746
- Business associate present
- Yes
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), QBE Holdings, Inc. reported that its business associate (BA), StayWell Health Management LLC, disclosed 1,746 individual’s protected health information on the internet. The PHI included names, email addresses, unique StayWell identification numbers, and information about participation in a wellness program. The BA provided breach notification to HHS and affected individuals. The BA also filed a separate breach report which was investigated by OCR. As a result of the breach, the BA implemented procedures to address the data compromise issue which included the performance of an initial analysis and risk assessment. Further, the BA implemented policies and procedures to safeguard PHI and trained its employees. OCR obtained assurances that the BA implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.