- State
- IL
- Covered entity type
- Business Associate
- Individuals affected
- 25,330
- Business associate present
- Yes
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), Gypsum Management & Supply, Inc. Medical and Dental Plan, is a management company for a network of drywall supply yards that offers group health plans for its employees. On May 9, 2011, the computer server of the CE’s former business associate (BA), Assurecare Risk Management, Inc., was hacked, exposing the demographic, clinical, and health insurance information for 25,330 of the CE’s employees, many of whom no longer worked with the CE at the time of the breach. The CE provided breach notification to HHS, to affected individuals, and to the media. Because the breach incident involved a BA and occurred prior to the September 23, 2013, compliance date, OCR verified that the CE had a proper BA agreement in place that restricted the BA’s use and disclosure of protected health information (PHI) and required the BA to safeguard all PHI. The CE’s internal investigation revealed little activity on the server as a result of the hack. In addition, no reports of misuse of information have been reported. OCR obtained assurances that the CE took the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.