Skip to content

Insurance Data Services

Disclosed Oct 8, 201510 years ago2,918 affectedConfirmed

Official notice

On September 15, 2015, a zippered bag was stolen from a delivery service vehicle with month-end reports for Insurance Data Services, a business associate (BA) of the covered entity (CE), Claystone Clinical Associates. The BA reported that this breach affected 2,918 individuals. The types of protected health information (PHI) involved in the breach included patients’ names, dates of service, balances, insurance providers, diagnostic and procedure codes, addresses, and phone numbers. The BA investigated the breach and assured that the theft was reported to the police. The BA provided breach notification to HHS, affected individuals, and the media. The BA also updated its procedures to utilize a secure client portal to transmit PHI with clients. As a result of OCR’s investigation the BA created policies and procedures relating to safeguarding PHI, using and disclosing PHI, and Breach Rule Notification and trained its staff on its policies. OCR obtained written assurances that the CE completed the corrective actions listed.

What is known

People affected2,918 (as reported to HHS)
DisclosedOct 8, 2015
AttackLost or stolen device
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Insurance Data Services (Business Associate, MI)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalOct 8, 20152,918
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Insurance Data Services

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.