Skip to content

New Jersey Department of Human Services

Disclosed Nov 22, 201312 years ago9,825 affectedConfirmed

Official notice

An employee of the covered entity's (CE) business associate (BA), Island Peer Review Organization, lost an unencrypted and not password-protected portable computer drive (a "USB" drive) that contained 9,825 patients’ names, addresses, dates of birth, social security numbers, clinical information, diagnoses, conditions, and identification numbers (including member identification, Medicaid identification, subscriber identification, patient account number and patient control number). The CE, New Jersey Department of Human Services, provided breach notification to HHS, and the BA notified affected individuals and the media. Following the breach, the BA recovered all of the USB drives used by employees and retrained these employees on the BA’s security policies and the appropriate use of encryption on portable electronic media. As a result of OCR’s investigation and technical assistance, the BA retrained certain staff and implemented a policy requiring staff to use only portable media purchased by the BA's Information Systems Department. The BA installed technical safeguards on all computers so only approved portable devices are allowed access while any other types can be rendered as “r

What is known

People affected9,825 (as reported to HHS)
DisclosedNov 22, 2013
AttackLost or stolen device
Data exposedNames, Health
SectorInsurance · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalNov 22, 20139,825

Other breaches at New Jersey Department of Human Services

BreachAffected
Disclosed Mar 25, 2020Mar 25, 20206 years agoHacking2,300
Disclosed Jun 15, 2018Jun 15, 20188 years agoInsider1,263
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about New Jersey Department of Human Services

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.