Gallant Risk & Insurance Services
Disclosed Jun 3, 201511 years ago995 affectedConfirmed
On April 4, 2015, laptop computers belonging to the business associate (BA), Gallant Risk & Insurance Services, Inc., were stolen due to an office break-in. The breach affected 995 individuals’ protected health information (PHI), including a combination of individuals’ names, addresses, dates of birth, social security numbers, group policy numbers, and insurance identification numbers. The BA reported the incident to local law enforcement and to the affected covered entities. In response to OCR’s investigation, the BA ensured the proper breach notifications were provided, increased physical security, increased technical safeguards for electronic PHI (such as utilizing additional encryption), and adopted HIPAA policies and procedures. OCR obtained documented assurances that the BA implemented these corrective steps..
What is known
| People affected | 995 (as reported to HHS) |
|---|---|
| Disclosed | Jun 3, 2015 |
| Happened | Apr 4, 2015 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Insurance · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| California Attorney General breach notice: Gallant Risk & Insurance Servicesoag.ca.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Gallant Risk & Insurance Services (Business Associate, CA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| California AGresidents of CA | Jun 3, 2015 | |
| HHS archivetotal | Jun 3, 2015 | 995 |
History of this record
- 2026-09-25 · attack: unknown to lost-device · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · records_basis: empty to hhs · backfill source
- 2026-09-25 · records: empty to 995 · backfill source
- 2026-09-25 · summary: empty to On April 4, 2015, laptop computers belonging to the business associate (BA), Gallant Risk & Insurance Services, Inc., were stolen due to an office break-in. The breach affected 995 individuals’ protected health information (PHI), including · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.