Skip to content

Minnesota Department of Human Services

Disclosed Jan 11, 20233 years ago4,307 affectedConfirmed

Official notice

The covered entity (CE), Minnesota Department of Human Services, reported that an employee inadvertently emailed billing statements that contained the protected health information (PHI) of 4,307 individuals to an unauthorized individual. The PHI involved included names, addresses, and claims and financial information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In response to the breach, the CE implemented additional administrative, technical, and security safeguards, and retrained workforce members to better protect its PHI. OCR provided technical assistance to the CE regarding the HIPAA Security Rule.

What is known

People affected4,307 (as reported to HHS)
DisclosedJan 11, 2023
AttackInsider
Data exposedNames, Health
SectorInsurance · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalJan 11, 20234,307

Other breaches at Minnesota Department of Human Services

BreachAffected
Disclosed Jan 16, 2026Jan 168 months agoInsider304K
Disclosed Aug 30, 2024Aug 30, 20242 years agoHacking4,329
Disclosed Oct 9, 2018Oct 9, 20187 years agoHacking21K
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Minnesota Department of Human Services

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.