- State
- MO
- Covered entity type
- Health Plan
- Individuals affected
- 935
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Other
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On February 18, 2011, a Union Security Insurance Co. policy holder notified the covered entity (CE) that while accessing their online account, they were also able to access the accounts of other policy holders. Approximately 1,500 individuals were affected by this breach. These accounts included names, dates of birth, social security numbers, and other identifiers. In addition, on May 17, 2013, an employee of the CE impermissibly emailed a spreadsheet which included identifiable data belonging to a customer group of the CE. Approximately 1,127 group members were affected by this breach. The email included names and social security numbers. The CE provided breach notification to HHS, affected individuals, and the media. To prevent similar breaches from happening in the future, the CE disabled its website, reversed the problematic coding, and increased the number of vulnerability scans of the CE’s website. The CE also retrained employees, to include distribution of its revised policy and procedure for safeguarding social security numbers. Following OCR’s investigation, the CE prohibited social security numbers on any document being sent to any customer. The CE provided OCR documentation that substantiates all its actions taken in response to the two breach incidents.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.