Huggins Insurance Services
Disclosed May 24, 20197 years ago667 affectedConfirmed
The business associate (BA), Huggins Insurance Services, reported that several employees were the victims of an email phishing scheme which affected the electronic protected health information (ePHI) of 5,725 individuals. The ePHI involved included names, addresses, dates of birth, drivers’ license information, Social Security numbers, claims information, financial data, and clinical information. The BA notified HHS, affected individuals, and the media. In its mitigation efforts, the BA implemented additional administrative, technical, and security safeguards and retrained its staff on the proper methods for identifying fraudulent email communications. OCR provided technical assistance to the BA regarding the provisions of the HIPAA Security Rule.
What is known
| People affected | 667 (as reported to HHS) |
|---|---|
| Disclosed | May 24, 2019 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Huggins Insurance Services (Business Associate, OR)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | May 24, 2019 | 667 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.