- State
- MO
- Covered entity type
- Health Plan
- Individuals affected
- 1,134
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On March 30, 2012, Hogan Services Inc. (HSI), the sponsor of a fully insured employee health plan, erroneously distributed an email to 287 employees containing the electronic protected health information (ePHI) of approximately 1,134 individuals. The ePHI included names, social security numbers, dates of birth, gender, group health plan identification numbers, member identifications, enrollment dates, and types of coverage for employees and names, dates of birth, and relationship information for employees’ spouses and dependents enrolled in the group health insurance plan. Upon discovering the breach, HSI directed its email vendor to shut down its email server, and constructed an incident response team that went to each workstation and deleted the ePHI from employees’ computers, and shredded any copies of the email that had been printed. HSI provided breach notification to HHS and affected individuals. As a result of OCR’s investigation, HSI made a decision not to accept, store, or transmit ePHI, and it retrained its workforce regarding the HIPAA Rules. HSI also added encryption software to employees’ accounts that have access to ePHI. OCR obtained assurances that HSI implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.