25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

122,000 Providence Health Plan Members Impacted by Dominion National Data Breach

In July 2019, Dominion National, an insurer and administrator of dental and vision benefits, announced the discovery of a major data breach that impacted around 2.9 million health plan members. Hackers had gained access to Dominion National servers in 2010. The breach was detected on April 24, 2019.

Providence Health Plan has recently announced the breach at Dominion National affected 122,000 of its plan members. Virginia-based Dominion National administers Providence Health Plan’s dental program in Oregon, and as such, had access to plan members’ protected health information (PHI), including names, addresses, dates of birth, insurance information, and Social Security numbers.

Dominion National started administering the health plan’s dental program in 2015. The breach was therefore limited to customers who participated in the dental program between 2015 and 2019.

Affected Providence Health Plan members were notified by Dominion National in August and have been offered two years of complimentary credit monitoring and identity theft protection services.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Laptop Theft from Business Associate Affects 7,358 Connally Memorial Medical Center Patients

Wilson County Memorial Hospital District is notifying 7,358 patients of Connally Memorial Medical Center in Floresville, Texas that some of their personal and health information has been exposed.

Patient information was stored on a laptop computer used by a business associate of the medical center. The laptop was stolen on April 23, 2019.

The unnamed business associate conducted a forensic analysis to determine what, if any, PHI was stored on the device. That analysis revealed a limited amount of PHI was stored in the memory of the laptop, which could possibly have been accessed by unauthorized individuals.

The majority of affected individuals only had their first and last name, date of birth, gender, ethnicity, specialty referral information, and an internal tracking number exposed. A smaller set of patients had their full name, diagnosis, reason for transfer, and transfer date exposed, along with the name of the hospital to where that individual was transferred.

The breach has prompted the medical center to update its business associate agreements to state that all business associates must now use encryption on laptops used to store or access patient information. No financial information or Social Security numbers were exposed, but out of an abundance of caution, affected individuals have been offered complimentary credit monitoring services for 12 months.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist