Skip to content

Texas Health and Human Services Commission

Disclosed Jun 14, 201610 years ago600 affectedConfirmed

Official notice

Between April 19, 2016 and May 10, 2016, Iron Mountain, a business associate (BA) of the covered entity (CE), Texas Health and Human Services Commission, was unable to locate sixteen cartons of records containing protected health information (PHI). The types of PHI involved in the breach included the names, addresses, social security numbers, social security claim numbers, dates of birth, medical record numbers, Medicaid/individual numbers, case numbers, and bank account numbers for over 500 individuals. The CE provided breach notification to HHS, affected individuals, and the media. Following the incident, the CE ensured that the BA retrained its workforce members on privacy and appropriate storage and tracking procedures. Additionally, the CE initiated a change to its procedure for reconciling file inventories and verifying file box destruction. OCR obtained assurances that the CE implemented the corrective actions noted above.

What is known

People affected600 (as reported to HHS)
DisclosedJun 14, 2016
AttackLost or stolen device
Data exposedNames, Health
SectorInsurance · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalJun 14, 2016600

Other breaches at Texas Health and Human Services Commission

BreachAffected
Disclosed Jan 16, 2025Jan 16, 20251 year agoHacking68K
Disclosed Sep 9, 2011Sep 9, 201115 years agoLost or stolen device1,696
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Texas Health and Human Services Commission

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.