New Avenues
Disclosed May 28, 20206 years ago1,000 affectedConfirmed
The covered entity (CE), New Avenues, reported that its business associate (BA) improperly disposed of the protected health information (PHI) of 1,000 individuals. The PHI involved included names, addresses, dates of birth, Social Security numbers, claims and financial information, diagnoses, lab results, and medication information. The CE notified HHS, affected individuals, the media, and provided substitute notice on its website. In response to the breach, the CE destroyed the mishandled PHI. The CE has terminated its business relationship with the BA.
What is known
| People affected | 1,000 (as reported by the organization) |
|---|---|
| Disclosed | May 28, 2020 |
| Happened | Apr 1, 2020 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Indiana Attorney General 2020 data breach report: New Avenuesin.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): New Avenues (Healthcare Provider, IN)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Indiana AGresidents of IN | May 28, 2020 | 1,000 |
| HHS archivetotal | May 28, 2020 | 1,000 |
History of this record
- 2026-09-25 · sector: other to health · backfill source
- 2026-09-25 · attack: unknown to lost-device · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · summary: empty to The covered entity (CE), New Avenues, reported that its business associate (BA) improperly disposed of the protected health information (PHI) of 1,000 individuals. The PHI involved included names, addresses, dates of birth, Social Security · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.