Skip to content

Agency for Health Care Administration

Disclosed Jan 5, 20188 years ago30,000 affectedConfirmed

Official notice

On November 20, 2017, the Agency for Health Care Administration, the covered entity (“CE”), discovered that one of its employees had been the victim of a phishing incident, potentially exposing the names, dates of birth, addresses, social security numbers, clinical and health insurance information of 29,641 individuals. The CE provided timely breach notification to HHS, to the affected individuals and to the media. At the time of the breach and currently, the CE trained its employees on its HIPAA policies and procedures and including the reporting of suspicious emails. In response to the breach, the CE retrained the employee at fault and its entire workforce on identifying and reporting potential phishing emails. OCR obtained assurances that the CE implemented the corrective actions listed above.

What is known

People affected30,000 (as reported to HHS)
DisclosedJan 5, 2018
AttackHacking
Data exposedNames, Health
SectorInsurance · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalJan 5, 201830,000
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Agency for Health Care Administration

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.