Skip to content

Amerigroup Iowa

Disclosed Mar 29, 20197 years ago1,191 affectedConfirmed

Official notice

Amerigroup Iowa, Inc., a business associate (BA) for the covered entity (CE), Iowa Department of Public Health, erroneously mailed letters to 1,191 of its minor members which contained the incorrect parent or guardian’s name. The type of protected health information (PHI) included in the breach included demographic and clinical information. The BA provided breach notification to affected individuals on behalf of the CE. Upon discovery of the breach incident on January 29, 2019, the BA investigated and determined that the incident resulted from a human error. Based on the breach, the BA sanctioned and retrained the responsible employee, revised its procedure for generating a member mailing list, and trained all workforce member on its updated procedure. OCR obtained assurances that the CE/BA implemented the corrective actions listed above.

What is known

People affected1,191 (as reported to HHS)
DisclosedMar 29, 2019
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Amerigroup Iowa (Business Associate, IA)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalMar 29, 20191,191

Other breaches at Amerigroup Iowa

BreachAffected
Disclosed Jan 3, 2024Jan 3, 20242 years agoInsider1,023
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Amerigroup Iowa

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.