- State
- WY
- Covered entity type
- Business Associate
- Individuals affected
- 2,700
- Business associate present
- Yes
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Desktop Computer
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Hansen and Associates, Inc., the covered entity (CE), reported that between May 21, 2013, and May 29, 2013, its employee inappropriately used her workstation in violation of its policies on multiple occasions. The employee added software programs that allowed her to remotely access a desktop computer from her personal computer and store information in the cloud for personal access. The employee’s conduct temporarily affected the CE’s ability to access protected health information (PHI) maintained on the workstation. The breach affected 2,700 individuals and the types of PHI involved included, names, social security numbers, addresses, date of births, claims, and clinical diagnoses and conditions. The CE provided breach notification to the affected individuals, the media, and HHS. Upon discovering the breach, the CE conducted an internal investigation with assistance from an information technology vendor; notified local law enforcement regarding its employee’s misconduct; implemented physical, administrative, and security safeguards in response to the subject incident; and drafted new policies and procedures regarding its obligations under the Privacy, Security, and Breach Notification Rules. OCR obtained assurances that the CE implemented the corrective actions noted above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.