SMC Corporation of America
Disclosed Feb 3, 20251 year ago6,566 affectedConfirmed
The covered entity (CE), SMC Corporation of America, reported that it was the subject of a cybersecurity incident that affected the protected health information of 6,566 individuals. The PHI involved included names, Social Security numbers, addresses, drivers’ license numbers, dates of birth, diagnoses/conditions, and other treatment information. The CE notified HHS and the affected individuals. In response to the breach, the CE provided complimentary credit monitoring services to the affected individuals and implemented additional administrative, technical, and security safeguards to better protect its PHI.
What is known
| People affected | 6,566 (as reported by the organization) |
|---|---|
| Disclosed | Feb 3, 2025 |
| Happened | Dec 3, 2024 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Insurance · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Indiana Attorney General 2025 data breach report: SMC Corporation of Americain.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): SMC Corporation of America (Health Plan, IN)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Indiana AGresidents of IN | Feb 3, 2025 | 3,655 |
| HHS archivetotal | Feb 27, 2025 | 6,566 |
History of this record
- 2026-09-25 · sector: other to insurance · backfill source
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · summary: empty to The covered entity (CE), SMC Corporation of America, reported that it was the subject of a cybersecurity incident that affected the protected health information of 6,566 individuals. The PHI involved included names, Social Security numbers, · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.