TSYS Employee Health Plan
Disclosed Oct 2, 201312 years ago5,232 affectedConfirmed
TSYS Employee Health Plan, the covered entity (CE), discovered that an employee of the CE’s business associate (BA), Paragon Benefits, Inc., misappropriated a digital file that contained protected health information (PHI) for 5,232 beneficiaries. The CE sent timely breach notification to HHS, to affected individuals, to the media and posted substitute notification on its website. In response to the breach, the CE provided affected individuals with identity theft protection, credit monitoring, tax forms, contact information for the Federal Trade Commission, and instructions on how to put a credit freeze on a credit account. OCR determined that the CE and BA had an effective BA agreement in place at the time of the breach. The CE terminated its contract with the BA as of December 31, 2012, but the BA continues to provide services for outstanding claims that it submitted on the CE’s behalf. The CE obtained assurances from the BA that additional security measures have been implemented. OCR obtained assurances that the CE implemented the corrective actions listed above.
What is known
| People affected | 5,232 (as reported to HHS) |
|---|---|
| Disclosed | Oct 2, 2013 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Insurance · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): TSYS Employee Health Plan (Health Plan, GA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Oct 2, 2013 | 5,232 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.