Skip to content

Iowa Department of Human Services

Disclosed Jan 27, 20206 years ago4,501 affectedConfirmed

Official notice

The covered entity (CE), Iowa Department of Human Services, reported that an employee of its custodial vendor, improperly disposed of documents containing the protected health information (PHI) of approximately 4,501 individuals. The PHI involved included names, addresses, dates of birth, drivers’ license information, Social Security numbers, diagnoses/conditions, medications prescribed, health insurance information, and financial data. The CE notified HHS, affected individuals, the media, and provided a toll free number for questions or concerns. The CE also offered complimentary credit monitoring services for affected individuals. In its mitigation efforts and as a result of OCR’s investigation, the CE implemented physical and administrative safeguards to better protect its PHI. OCR obtained assurances that the CE implemented the corrective actions noted.

What is known

People affected4,501 (as reported to HHS)
DisclosedJan 27, 2020
AttackLost or stolen device
Data exposedNames, Health
SectorInsurance · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalJan 27, 20204,501

Other breaches at Iowa Department of Human Services

BreachAffected
Disclosed Oct 20, 2017Oct 20, 20178 years agoHacking811
Disclosed Jun 26, 2013Jun 26, 201313 years agoLost or stolen device7,335
Disclosed May 11, 2012May 11, 201214 years agoLost or stolen device3,000
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Iowa Department of Human Services

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.