Iowa Department of Health and Human Services
Disclosed May 26, 20233 years ago833 affectedConfirmed
The covered entity (CE), Iowa Department of Health and Human Services, reported that an employee of its business associate (BA) inadvertently mailed the protected health information (PHI) of 833 individuals to the wrong recipients. The PHI involved included names, health insurance information, claims information, diagnoses, and other treatment information. The CE notified HHS, the media, and posted substitute notice on its website; the BA notified affected individuals. In response to the breach, the BA sanctioned the responsible employee and retrained its workforce on patient privacy and security.
What is known
| People affected | 833 (as reported to HHS) |
|---|---|
| Disclosed | May 26, 2023 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Insurance · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Iowa Department of Health and Human Services (Health Plan, IA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | May 26, 2023 | 833 |
Other breaches at Iowa Department of Health and Human Services
| Breach | Affected | ||||
|---|---|---|---|---|---|
| Disclosed Apr 16, 2026Apr 165 months agoInsider | Apr 165 months ago | Insider | Insurance | Confirmed | 6,717 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.
Everything about Iowa Department of Health and Human Services