- State
- WY
- Covered entity type
- Health Plan
- Individuals affected
- 11,935
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), Wyoming Department of Health, transferred a copy of the Women Infants and Children benefit program backup database via the internet to a business associate using an unsecured method. Approximately 11,935 individuals were affected by the breach, potentially disclosing demographic information, dates of birth, gender, and identification numbers. The CE notified affected individuals, the media, and the Secretary. Following OCR’s investigation, the CE conducted an enterprise-wide risk analysis, developed a risk management plan, and revised its organizational structure in order to hybridize into covered and non-covered functions. OCR obtained assurances that the CE implemented these corrective action steps.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.