- State
- IA
- Covered entity type
- Health Plan
- Individuals affected
- 2,042
- Business associate present
- No
- Type of breach
- Other
- Location of breached information
- Email, Laptop, Other Portable Electronic Device
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Employees of the covered entity (CE), Iowa Department of Human Services, used personal email accounts, personal online storage accounts and personal electronic devices for work purposes. From February 5, 2010 to January 17, 2014, the protected health information (PHI) of 2,042 individuals was transferred outside of the CE’s secure network in this manner. The types of information included names, mailing addresses, social security numbers, state ID numbers, dates of birth, PHI obtained during case assessment, and incident information. The CE stated that it notified affected individuals and media and also offered free credit monitoring to the affected individuals. OCR has consolidated this breach with another breach involving this CE.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.