Skip to content

Iowa Medicaid Enterprise

Disclosed Apr 25, 201412 years ago862 affectedConfirmed

Official notice

On August 5, 2015, the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR), Midwest Region initiated a review of the covered entity (CE), Iowa Department of Human Services. This review stems from a complaint and security breaches that the CE self-reported to OCR-HQ (as required by 45 CFR § 164.408(b)), which occurred over a period of nine years from 2005 to 2014. The CE provided breach notification to HHS, affected individuals, and the media. To prevent similar breaches from happening in the future, the CE conducted multiple internal investigations, evidenced the performance of its risk analysis and corresponding risk management plan. It also sanctioned the employees involved in the breach incidents, provided training to its staff on its policies and procedures regarding Security Awareness. Additionally, the CE implemented annual security control reviews that assess its compliance with the Privacy, Security, and Breach Notification Rules and implemented new HIPAA policies and procedures. OCR obtained copies of the CE's executed business associate agreements and documentation that substantiates the CE's corrective actions described above.

What is known

People affected862 (as reported to HHS)
DisclosedApr 25, 2014
AttackInsider
Data exposedNames, Health
SectorInsurance · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Iowa Medicaid Enterprise (Health Plan, IA)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalApr 25, 2014862
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Iowa Medicaid Enterprise

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.