Iowa Department of Health and Human Services
ent_6f5955a88811a263d36516ec
Disclosures
8
HHS OCR · 1 jurisdiction
Incidents
—
no linked incident in sample
Max affected reported
233,834
nationwide · HHS OCR IA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Iowa Department of Health and Human Services
- Normalized
- iowa department of health and human— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (8)newest first
- IOWAHHS OCRas victim2026-01-06
Iowa Health and Human Services reported to HHS on 2026-01-06 a Hacking/IT Incident affecting 3340 individuals. Breached information located on Network Server. Business associate was present.
- IOWAHHS OCRas victim2023-05-30
Iowa Department of Health and Human Services - Iowa Medicaid reported to HHS on 2023-05-30 a Hacking/IT Incident affecting 233,834 individuals. Breached information located on Network Server. A business associate was the victim of a cyber-attack. The CE provided complimentary credit monitoring and implemented additional technical safeguards.
- IOWAHHS OCRas victim2023-05-26
Iowa Department of Health and Human Services reported to HHS on 2023-05-26 a Unauthorized Access/Disclosure affecting 833 individuals. Breached information located on Paper/Films. An employee of a business associate inadvertently mailed PHI (names, health insurance, claims, diagnoses, treatment info) to wrong recipients. The CE notified HHS and media; the BA notified individuals, sanctioned the employee, and retrained staff.
- IOWAHHS OCRas victim2020-01-27
Iowa Department of Human Services reported to HHS on 2020-01-27 an Improper Disposal breach affecting 4,501 individuals. An employee of the entity's custodial vendor improperly disposed of documents containing PHI. Breached information was located on Paper/Films and included names, addresses, dates of birth, driver's license information, Social Security numbers, diagnoses/conditions, medications, health insurance information, and financial data. OCR investigated and obtained assurances that corrective actions — including physical and administrative safeguards — were implemented. Credit monitoring was offered to affected individuals.
- IOWAHHS OCRas victim2017-10-20
Iowa Department of Human Services reported to HHS on 2017-10-20 a Hacking/IT Incident affecting 811 individuals. Breached information located on Email. Employees were subject to an email phishing scheme exposing PHI including names, addresses, DOB, SSN, and medical data. Response included credit monitoring, technical safeguard strengthening, employee sanctions, and security retraining.
- IOWAHHS OCRas victim2014-03-10
Iowa Department of Human Services reported to HHS OCR on 2014-03-10 a breach (type: Other) affecting 2,042 individuals. From February 5, 2010 to January 17, 2014, employees used personal email accounts, personal online storage accounts, and personal electronic devices for work purposes, transferring PHI outside the CE's secure network. Breached info included names, mailing addresses, SSNs, state ID numbers, dates of birth, case assessment PHI, and incident information. Located on Email, Laptop, and Other Portable Electronic Devices. No business associate was present. Affected individuals were notified, media was notified, and free credit monitoring was offered. OCR has consolidated this breach with another breach involving this CE.
- IOWAHHS OCRas victim2013-06-26
Iowa Department of Human Services reported to HHS OCR on 2013-06-26 a Loss (Unknown) breach affecting 7,335 individuals. The breached information was located on an 'Other' type of medium. No business associate was present. The breach type is listed as 'Loss, Unknown,' indicating the circumstances of the loss were undetermined at the time of submission.
- IOWAHHS OCRas victim2012-05-11
Iowa Department of Human Services reported to HHS on 2012-05-11 a Improper Disposal affecting 3000 individuals. Breached information located on Paper/Films.