25% off all training courses Offer ends July 30, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends July 30, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

TriWest Healthcare Alliance Announced Breach Affecting Almost 12,000 Tricare Beneficiaries

Data breaches have been announced by TriWest Healthcare Alliance, Texas Medicaid and Healthcare Partnership, the Minnesota Health Insurance Network, and Secure Health Plans of Georgia.

TriWest Healthcare Alliance

TriWest Healthcare Alliance, a contractor that manages care for active duty, retired, and National Guard and Reserve military personnel and their family members under the United States Department of Veterans Affairs VAPCCC program, has shared information on a data breach reported to the HHS’ Office for Civil Rights on May 21, 2026. According to the OCR breach report, the protected health information of 11,848 individuals was potentially compromised in the incident.

The security incident was first identified on April 16, 2026. The forensic investigation confirmed that an unauthorized third party gained limited access to parts of its network and downloaded files containing protected health information. Data compromised in the incident includes names, Department of Defense Benefits Numbers, beneficiaries’ ZIP codes, and health-related information. Only 5 individuals had their addresses, dates of birth, and Social Security numbers stolen.

At the time of issuing notification letters, some of which were sent on July 2, 2026, no misuse of the impacted information had been identified; however, as a precaution against data misuse, the affected individuals have been offered complimentary credit monitoring services for 24 months. Security controls have been enhanced, system monitoring tools have been strengthened, and additional security awareness training has been provided to its workforce.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Texas Medicaid and Healthcare Partnership

Texas Medicaid and Healthcare Partnership (TMHP), a state Medicaid contractor, has recently reported a data breach to the HHS’ Office for Civil Rights involving the protected health information of 2,045 individuals.  According to the TMHP substitute data breach notice, this was a fraud-related incident that involved unauthorized access to certain internal systems between February 5, 2026, and March 26, 2026.

When the unauthorized access was detected, immediate action was taken to contain the incident and secure its network, and additional security measures have been implemented to harden security. The forensic investigation determined on April 20, 2026, that personal and protected health information of 1,828 Medicaid clients and 217 healthcare providers had been exposed.

For Medicaid clients, the data compromised in the incident included full names, addresses, dates of birth, Social Security numbers, Medicaid numbers, Medicaid benefits information, Medicaid card information, and health information. Healthcare provider information included full names, addresses, emails, medical license information, financial information, driver’s license numbers, Social Security numbers, tax identification numbers, and other provider enrollment management system information.

Notification letters were mailed to the affected individuals on June 18, 2026, who have been offered complimentary identity theft protection and identity recovery services. TMHP said that at the time of issuing notifications, no information had been found to indicate any actual or attempted misuse of the impacted information.

Minnesota Health Insurance Network

Minnesota Health Insurance Network, a Burnsville, MN-based health insurance brokerage, has started notifying individuals about a recent security incident that exposed personal and protected health information. The security incident was identified on March 17, 2026, and its forensic investigation determined that there had been unauthorized access to parts of its network between March 16 and March 17, 2026, during which time files were exfiltrated from its network.

The affected data has been reviewed and found to include names, dates of birth, Social Security numbers, driver’s license/state ID numbers, other government-issued ID numbers, financial account numbers, credit/debit card information, diagnosis and treatment information, and health insurance information. Individuals whose Social Security numbers were involved have been offered complimentary credit monitoring services. While regulators have been notified, the incident is not currently listed on the HHS’ Office for Civil Rights website, so it is unclear how many individuals have been affected.

Secure Health Plans of Georgia

Secure Health Plans of Georgia (Secure Health), a provider of administrative services, care management, and healthy lifestyle programs to employers with self-funded health benefit plans, is reviewing files that were exposed in a recent cybersecurity incident. The incident was identified on February 12, 2026, and the forensic investigation confirmed unauthorized access to its systems on or before February 3, 2026, until February 12, 2026. During that time, files containing individuals’ protected health information may have been viewed or copied. Secure Health has not yet confirmed the exact types of information exposed in the incident, although protected health information was exposed.

The incident has been reported to the HHS’ Office for Civil Rights using a placeholder estimate of at least 501 individuals. The total will be updated when the data review is concluded, and notification letters will be mailed stating the types of data involved. Secure Health has taken steps to strengthen security to prevent similar incidents in the future.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist