Local 295 IBT Employer Group Welfare Fund
Disclosed Mar 11, 20224 years ago6,123 affectedConfirmed
The covered entity (CE), Local 295 IBT Employer Group Welfare Fund, reported that its business associate (BA) experienced a cybersecurity attack that affected the protected health information (PHI) of 6,123 individuals. The PHI involved included names, addresses, dates of birth, and Social Security numbers. The CE notified HHS; the BA notified affected individuals, the media, and law enforcement. In its mitigation efforts, the BA implemented additional administrative safeguards and retrained its employees in an effort to better protect PHI. OCR provided technical assistance to the CE regarding the HIPAA Privacy Rule.
What is known
| People affected | 6,123 (as reported to HHS) |
|---|---|
| Disclosed | Mar 11, 2022 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Insurance · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Local 295 IBT Employer Group Welfare Fund (Health Plan, NY)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Mar 11, 2022 | 6,123 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.