Back to the register

TSYS Employee Health Plan

ArchivedSubmitted 10/02/2013
State
GA
Covered entity type
Health Plan
Individuals affected
5,232
Business associate present
Yes
Type of breach
Theft
Location of breached information
Email
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

TSYS Employee Health Plan, the covered entity (CE), discovered that an employee of the CE’s business associate (BA), Paragon Benefits, Inc., misappropriated a digital file that contained protected health information (PHI) for 5,232 beneficiaries. The CE sent timely breach notification to HHS, to affected individuals, to the media and posted substitute notification on its website. In response to the breach, the CE provided affected individuals with identity theft protection, credit monitoring, tax forms, contact information for the Federal Trade Commission, and instructions on how to put a credit freeze on a credit account. OCR determined that the CE and BA had an effective BA agreement in place at the time of the breach. The CE terminated its contract with the BA as of December 31, 2012, but the BA continues to provide services for outstanding claims that it submitted on the CE’s behalf. The CE obtained assurances from the BA that additional security measures have been implemented. OCR obtained assurances that the CE implemented the corrective actions listed above.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.