Texas Health and Human Services Commission
ent_3e1047a78a64c35a2438b69c
Disclosures
7
HHS OCR · HHS OCR enforcement · 2 jurisdictions
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
94,261
nationwide · HHS OCR TX
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Texas Health and Human Services Commission
- Normalized
- texas health and human services commission— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (7)newest first
- TEXASHHS OCRas victim2026-01-05
Texas Health and Human Services Commission reported to HHS on 2026-01-05 a Hacking/IT Incident affecting 68066 individuals. Breached information located on Network Server. Business associate present.
- TEXASHHS OCRas victim2025-01-16
Texas Health and Human Services Commission reported to HHS on 2025-01-16 an Unauthorized Access/Disclosure affecting 94,261 individuals. PHI including names, SSNs, financial info, and treatment data was inappropriately accessed by workforce members. Breached information located on Desktop Computer, Laptop.
- TEXASHHS OCRas victim2024-03-11
Texas Health and Human Services reported to HHS on 2024-03-11 a Unauthorized Access/Disclosure affecting 3392 individuals. Breached information located on Email. An employee emailed PHI (names, SSNs, diagnoses) to a personal account. CE provided credit monitoring and implemented technical safeguards.
- FEDERALHHS OCR enforcementas victim2019-11-07
HHS OCR imposed a $1.6 million civil money penalty on the Texas Health and Human Services Commission (TX HHSC) for HIPAA Privacy and Security Rule violations occurring between 2013 and 2017.
- TEXASHHS OCRas victim2017-06-15
Texas Health and Human Services Commission (HHSC) reported to HHS OCR on 2017-06-15 an Improper Disposal breach affecting 1,842 individuals. A workforce member improperly discarded several boxes of PHI into a public dumpster. Not all boxes were retrieved. PHI involved included names, addresses, dates of birth, Social Security numbers, financial information, and treatment information. HHSC sanctioned the employee, retrained all staff on PHI disposal, notified affected individuals and media, and offered one year of free credit monitoring.
- TEXASHHS OCRas victim2016-06-14
Texas Health and Human Services Commission (TX Health Plan) reported to HHS on 2016-06-14 a Loss of Paper/Films affecting 600 individuals. Between April 19 and May 10, 2016, Iron Mountain, a business associate, was unable to locate sixteen cartons of records containing PHI, including names, addresses, SSNs, dates of birth, medical record numbers, Medicaid/individual numbers, case numbers, and bank account numbers. CE notified HHS, affected individuals, and media; BA retrained staff; CE revised file inventory reconciliation and box destruction procedures. OCR obtained assurances of corrective action.
- TEXASHHS OCRas victim2011-09-09
Texas Health and Human Services Commission reported to HHS OCR on 2011-09-09 a Theft affecting 1,696 individuals. An unencrypted laptop was stolen from an employee's vehicle containing ePHI including patient names, dates of birth, gender, Medicaid identification numbers, procedure codes, and diagnoses. The CE notified affected patients and the media, confirmed laptop encryption per policy, and sanctioned three involved employees.