Iowa Department of Health and Human Services - Iowa Medicaid
Disclosed May 30, 20233 years ago233,834 affectedConfirmed
The covered entity (CE), Iowa Department of Health and Human Services - Iowa Medicaid, reported that its business associate (BA) was the victim of a cyber-attack affecting the protected health information (PHI) of 233,834. The PHI involved included names, addresses, dates of birth, drivers’ license numbers, Social Security numbers, claims and financial information, diagnoses, medications, and dental records. The CE notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the CE provided complimentary credit monitoring services to affected individuals and implemented additional technical safeguards.
What is known
| People affected | 233,834 (as reported to HHS) |
|---|---|
| Disclosed | May 30, 2023 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Insurance · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Iowa Department of Health and Human Services - Iowa Medicaid (Health Plan, IA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | May 30, 2023 | 233,834 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.
Everything about Iowa Department of Health and Human Services - Iowa Medicaid