INSURANCE OFFICE OF AMERICA, INC.
bd_a138b81ce46e7cf3 · schema v1 · pii pii-v1
Full breach record for INSURANCE OFFICE OF AMERICA, INC. →Insurance Office of America (IOA) notified individuals of a data breach occurring on May 14, 2026. An employee inadvertently attached a document containing personal information, including names, Social Security numbers, and protected health information (health insurance and benefit plan enrollment details), to a routine benefits-related email. IOA recalled the email, conducted an internal investigation, and obtained attestations from most recipients confirming deletion. IOA implemented enhanced safeguards, including additional staff training and strengthened review procedures for outbound communications. Affected individuals were offered 24 months of complimentary credit monitoring and identity protection services through Epiq. IOA stated there is no evidence of misuse.
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_903bdd447dbdcf37New Hampshire State AGfiled 2026-06-22(21d gap)Verified
Source provenance
- Source URL
- https://www.mass.gov/doc/2026-1012-insurance-office-of-america/download
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 1, 2026
- Raw hash
- 899ece19c222ba6665fe58669eab8694916e9a70043ff2cbe1b31e3fd2a3b93e
Reporting entity
- Name
- INSURANCE OFFICE OF AMERICA, INC.norm: insurance office of america
- Domain
- ioausa.com
Victim entity
- Name
- INSURANCE OFFICE OF AMERICA, INC.norm: insurance office of america
- Domain
- ioausa.com
Incident
- Discovered
- May 14, 2026
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1566 Phishing
- Threat actor
- Internal
Compliance
- Time to disclose
- 18 days(18 days from discovery to filing)
- Compliance flags
- Leak >180dMA AG ≤30d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.