Infosys Public Services
Disclosed Jan 31, 20251 year ago2,985 affectedConfirmed
Infosys Public Services, the business associate (BA) reported that an employee of its subcontractor uploaded the protected health information (PHI) of 2,985 individuals to the Internet. The PHI involved included names, addresses, dates of birth, claims and health insurance information, diagnoses, and other treatment information. To reduce the likelihood of a similar event occurring in the future, Infosys terminated its business relationship with the subcontractor and retrained employees on proper procedures for handling PHI.
What is known
| People affected | 2,985 (as reported to HHS) |
|---|---|
| Disclosed | Jan 31, 2025 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Infosys Public Services (Business Associate, MD)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jan 31, 2025 | 2,985 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.