Shiel Sexton
Disclosed Jan 27, 20179 years ago710 affectedConfirmed
On January 10, 2017, Shiel Sexton learned that its former business associate (BA), HCH Administration, Inc., had disclosed protected health information (PHI) in 2012 to a reinsurer beyond the minimum necessary requirements in the business associate agreement (BAA) with Shiel Sexton. The breach affected 710 individuals and the types of PHI involved included names and social security numbers. The covered entity (CE) provided breach notification to affected individuals and the media on January 27, 2017, and also notified HHS. OCR obtained documented assurances that the CE implemented these corrective action steps. During the course of this investigation, OCR learned that the BA dissolved its business in 2013.
What is known
| People affected | 710 (as reported to HHS) |
|---|---|
| Disclosed | Jan 27, 2017 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Insurance · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Shiel Sexton (Health Plan, IN)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jan 27, 2017 | 710 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.