Iowa Medicaid Enterprise
Disclosed Apr 25, 201412 years ago862 affectedConfirmed
On August 5, 2015, the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR), Midwest Region initiated a review of the covered entity (CE), Iowa Department of Human Services. This review stems from a complaint and security breaches that the CE self-reported to OCR-HQ (as required by 45 CFR § 164.408(b)), which occurred over a period of nine years from 2005 to 2014. The CE provided breach notification to HHS, affected individuals, and the media. To prevent similar breaches from happening in the future, the CE conducted multiple internal investigations, evidenced the performance of its risk analysis and corresponding risk management plan. It also sanctioned the employees involved in the breach incidents, provided training to its staff on its policies and procedures regarding Security Awareness. Additionally, the CE implemented annual security control reviews that assess its compliance with the Privacy, Security, and Breach Notification Rules and implemented new HIPAA policies and procedures. OCR obtained copies of the CE's executed business associate agreements and documentation that substantiates the CE's corrective actions described above.
What is known
| People affected | 862 (as reported to HHS) |
|---|---|
| Disclosed | Apr 25, 2014 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Insurance · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Iowa Medicaid Enterprise (Health Plan, IA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Apr 25, 2014 | 862 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.