Healthcare Administrative Partners
Disclosed Nov 5, 20196 years ago17,693 affectedConfirmed
Healthcare Administrative Partners, a business associate (BA), reported that an employee was the victim of an email phishing scheme that affected the electronic protected health information (ePHI) of 17,693 individuals. The ePHI involved included names, addresses, birthdates, and diagnoses. The BA notified HHS, affected individuals, the media, and provided a toll-free phone number for questions or concerns. In its mitigation efforts, the BA implemented additional administrative, technical, and security safeguards to better protect its sensitive data. The BA also retrained its staff on the proper methods of identifying fraudulent email communications.
What is known
| People affected | 17,693 (as reported to HHS) |
|---|---|
| Disclosed | Nov 5, 2019 |
| Discovered | Sep 16, 2019 |
| Happened | Jun 26, 2019 |
| Attack | Hacking |
| Data exposed | Names, Social Security numbers, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Indiana Attorney General 2019 data breach report: Healthcare Administrative Partnersin.gov · Official notice | Official notice |
| Maine Attorney General breach notice archive: Healthcare Administrative Partnersmaine.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Healthcare Administrative Partners (Business Associate, PA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Maine AGresidents of ME | Nov 5, 2019 | 4 |
| Indiana AGresidents of IN | Nov 6, 2019 | 1 |
| HHS archivetotal | Dec 3, 2019 | 17,693 |
History of this record
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: ["names","ssn"] to ["names","ssn","health"] · backfill source
- 2026-09-25 · records_basis: organization to hhs · backfill source
- 2026-09-25 · records: 200 to 17693 · backfill source
- 2026-09-25 · summary: empty to Healthcare Administrative Partners, a business associate (BA), reported that an employee was the victim of an email phishing scheme that affected the electronic protected health information (ePHI) of 17,693 individuals. The ePHI involved in · backfill source
- 2026-09-25 · data_types: [] to ["names","ssn"] · backfill source
- 2026-09-25 · disclosed: 2019-11-06 to 2019-11-05 · backfill source
- 2026-09-25 · discovered: empty to 2019-09-16 · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.