Hansen and Associates
Disclosed Jul 15, 201313 years ago2,700 affectedConfirmed
Hansen and Associates, Inc., the covered entity (CE), reported that between May 21, 2013, and May 29, 2013, its employee inappropriately used her workstation in violation of its policies on multiple occasions. The employee added software programs that allowed her to remotely access a desktop computer from her personal computer and store information in the cloud for personal access. The employee’s conduct temporarily affected the CE’s ability to access protected health information (PHI) maintained on the workstation. The breach affected 2,700 individuals and the types of PHI involved included, names, social security numbers, addresses, date of births, claims, and clinical diagnoses and conditions. The CE provided breach notification to the affected individuals, the media, and HHS. Upon discovering the breach, the CE conducted an internal investigation with assistance from an information technology vendor; notified local law enforcement regarding its employee’s misconduct; implemented physical, administrative, and security safeguards in response to the subject incident; and drafted new policies and procedures regarding its obligations under the Privacy, Security, and Breach Notificat
What is known
| People affected | 2,700 (as reported to HHS) |
|---|---|
| Disclosed | Jul 15, 2013 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Hansen and Associates (Business Associate, WY)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jul 15, 2013 | 2,700 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.