NPS
Disclosed Apr 28, 20215 years ago1,119 affectedConfirmed
The covered entity (CE), NPS Corporation, reported that it experienced a cyber-attack that compromised the protected health information (PHI) of approximately 999 individuals. The PHI involved included names, addresses, dates of birth, drivers’ license and Social Security numbers, claims and financial information, and diagnoses. The CE notified HHS, the affected individuals, and the media. In its mitigation efforts, the CE offered free credit monitoring services and enabled multifactor authentication for remote access, and created and revised relevant HIPAA Security Rule policies and procedures.
What is known
| People affected | 1,119 (as reported by the organization) |
|---|---|
| Disclosed | Apr 28, 2021 |
| Happened | Feb 12, 2021 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Insurance · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Indiana Attorney General 2021 data breach report: NPSin.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): NPS (Health Plan, WI)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Indiana AGresidents of IN | Apr 28, 2021 | 1 |
| HHS archivetotal | Apr 28, 2021 | 999 |
History of this record
- 2026-09-25 · sector: other to insurance · backfill source
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · summary: empty to The covered entity (CE), NPS Corporation, reported that it experienced a cyber-attack that compromised the protected health information (PHI) of approximately 999 individuals. The PHI involved included names, addresses, dates of birth, driv · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.