Skip to content

West Virginia Public Employees Insurance Agency

Disclosed Feb 27, 20197 years ago1,400 affectedConfirmed

Official notice

By purporting to be healthcare providers, unauthorized users registered for a portal operated by Availity, a subcontractor of the covered entity’s (CE) business associate (BA), Humana, gaining access to protected health information (PHI) for a period of six months. The breach affected approximately 1,400 individuals, including the PHI of 39 members of this CE, such as names, insurance identification numbers, benefit information, and care reminders. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE obtained written assurances from Availity that it implemented technical safeguards to limit the risk of such incidents in the future, and obtained written assurances from the BA regarding the HIPAA compliance of its subcontractors. OCR reviewed the CE’s BA agreement and opened a separate investigation of the Humana breach involving the subcontractor.

What is known

People affected1,400 (as reported to HHS)
DisclosedFeb 27, 2019
AttackHacking
Data exposedNames, Health
SectorInsurance · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalFeb 27, 20191,400
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about West Virginia Public Employees Insurance Agency

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.