Back to the register
Ashley Industrial Molding, Inc. Employee Welfare Benefit Plan
ArchivedSubmitted 08/08/2011
- State
- IN
- Covered entity type
- Business Associate
- Individuals affected
- 506
- Business associate present
- Yes
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
A computer server belonging to a former business associate (BA) and third party administrator, AssureCare Risk Management, Inc., was hacked. The server contained social security numbers, birth dates, names, addresses, gender, and physician and hospital/facility names linked with benefit payment information which could include type of service (i.e. office visit, inpatient stay, lab and x-ray, physical therapy, etc.). The breach affected 506 individuals. The relationship between the BA and the covered entity, Ashley Industrial Molding, Inc. Employee Welfare Benefit Plan, ended in 2006, but the BA continued to retain possession of protected health information (PHI) relating to the Plan’s participants because it was required to do so by law. The CE provided breach notification to HHS, affected individuals, and the media. OCR reviewed the BA agreement between the BA and CE which contained provisions regarding the use, disclosure, and safeguarding of PHI that ended in 2006, but also contained language requiring the BA to extend the protections of the agreement to the CE’s PHI after the agreement terminated. The CE obtained assurances that the BA shut down the server in question following the breach and does not maintain unsecured PHI on any other server. OCR obtained written assurances that the CE implemented the corrective actions noted above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.