Skip to content

KEYSTONE INSURERS GROUP

Disclosed May 6, 201412 years ago1,008 affectedConfirmed

Official notice

The covered entity (CE), City of Henderson, discovered that on several occasions between January 23, 2013, and March 3, 2013, its business associate (BA) broker, Keystone Insurers Group, disclosed more than the minimum necessary information to several health care providers who were being considered as a possible partner with the City in development of a City-run healthcare clinic. The BA had been hired to assist in the evaluation process of determining whether a City-operated health clinic would reduce health care costs. The types of protected health information (PHI) involved in the breach included demographic information such as names, insurance numbers, addresses, birthdates, and clinical information, such as diagnoses, treatment, prescriptions, and expenses. The CE provided breach notification to HHS, affected individuals, and the media, and posted substitute notice on its website. In response to the incident, the CE obtained certificates of deletion and destruction from the recipients of the PHI and it terminated its agreement with the BA. The CE also revised its request for proposals process to include information about potential brokers’ HIPAA training and any prior HIPAA br

What is known

People affected1,008 (as reported to HHS)
DisclosedMay 6, 2014
AttackNot stated
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): KEYSTONE INSURERS GROUP (Business Associate, IN)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalMay 6, 20141,008
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about KEYSTONE INSURERS GROUP

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.