Insurance Office of America (IOA) notified individuals of a data breach occurring on May 14, 2026. An employee inadvertently attached a document containing personal information, including names, Social Security numbers, and protected health information (health insurance and benefit plan enrollment details), to a routine benefits-related email. IOA recalled the email, conducted an internal investigation, and obtained attestations from most recipients confirming deletion. IOA implemented enhanced safeguards, including additional staff training and strengthened review procedures for outbound communications. Affected individuals were offered 24 months of complimentary credit monitoring and identity protection services through Epiq. IOA stated there is no evidence of misuse.