West Virginia Public Employees Insurance Agency
Disclosed Feb 27, 20197 years ago1,400 affectedConfirmed
By purporting to be healthcare providers, unauthorized users registered for a portal operated by Availity, a subcontractor of the covered entity’s (CE) business associate (BA), Humana, gaining access to protected health information (PHI) for a period of six months. The breach affected approximately 1,400 individuals, including the PHI of 39 members of this CE, such as names, insurance identification numbers, benefit information, and care reminders. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE obtained written assurances from Availity that it implemented technical safeguards to limit the risk of such incidents in the future, and obtained written assurances from the BA regarding the HIPAA compliance of its subcontractors. OCR reviewed the CE’s BA agreement and opened a separate investigation of the Humana breach involving the subcontractor.
What is known
| People affected | 1,400 (as reported to HHS) |
|---|---|
| Disclosed | Feb 27, 2019 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Insurance · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): West Virginia Public Employees Insurance Agency (Health Plan, WV)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Feb 27, 2019 | 1,400 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.
Everything about West Virginia Public Employees Insurance Agency