VIVA Health
Disclosed Sep 26, 202512 months ago4,945 affectedConfirmed
The covered entity (CE), VIVA Health, reported that an employee mistakenly posted the protected health information (PHI) of 4,945 individuals to its website. The PHI involved included demographic and clinical information. The CE notified HHS, the affected individuals, and the media, and provided substitute notice. In response to the breach, the CE provided complimentary credit monitoring services to the affected individuals, implemented additional administrative, technical, and security safeguards, and retrained workforce members to better protect its PHI.
What is known
| People affected | 4,945 (as reported to HHS) |
|---|---|
| Disclosed | Sep 26, 2025 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Insurance · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): VIVA Health (Health Plan, AL)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Sep 26, 2025 | 4,945 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.