Skip to content

NCH

Disclosed Jul 24, 20215 years ago13,824 affectedConfirmed

Official notice

The covered entity (CE), NCH Corporation, reported that it experienced a ransomware attack that compromised the protected health information (PHI) of 11,427 individuals. The PHI involved included names, birthdates, Social Security numbers, and health insurance information. The CE notified HHS, affected individuals, the media, and provided substitute notice on its website. In response to the breach, the CE implemented additional administrative and technical safeguards to better protect sensitive data. OCR provided technical assistance regarding the HIPAA Rules.

What is known

People affected13,824 (as reported by the organization)
DisclosedJul 24, 2021
HappenedMar 2, 2021
AttackHacking
Data exposedNames, Health
SectorRetail · US
StatusConfirmed

Sources

Source
Indiana Attorney General 2021 data breach report: NCHin.gov · Official notice
HHS OCR breach report (archive, resolved): NCH (Health Plan, TX)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalJul 24, 202111,427
Indiana AGresidents of INJul 29, 202153

Other breaches at NCH

BreachAffected
Disclosed Dec 5, 2025Dec 5, 20259 months ago4,732
Disclosed Jan 25, 2019Jan 25, 20197 years ago4,171
History of this record
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · disclosed: 2021-07-29 to 2021-07-24 · backfill source
  • 2026-09-25 · summary: empty to The covered entity (CE), NCH Corporation, reported that it experienced a ransomware attack that compromised the protected health information (PHI) of 11,427 individuals. The PHI involved included names, birthdates, Social Security numbers, · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.

Everything about NCH

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.