Decisely Insurance Services, LLC Data Breach
Decisely Insurance Services Breach Affects 537K Patients
What happened in the Decisely Insurance Services, LLC data breach?
The Decisely Insurance Services, LLC data breach was reported on June 13, 2025 and affected 537,603 individuals. The breach type was Hacking/IT Incident involving Network Server, Other. This breach occurred in Georgia. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Decisely Insurance Services, LLC Breach Details
Decisely Insurance Services Data Breach Report
Incident Overview
Decisely Insurance Services, LLC, a Georgia-based insurance services provider, experienced a significant data breach involving unauthorized access to its network servers. The breach was reported to the U.S. Department of Health and Human Services on June 13, 2025, affecting 537,603 individuals. This incident represents a substantial compromise of protected health information (PHI) maintained by the organization, which operates as a business associate to covered entities in the healthcare industry. The unauthorized access to network infrastructure suggests a sophisticated attack targeting the company's IT systems, potentially exposing sensitive patient and policyholder data to external threat actors.
Discovery and Response Timeline
While specific details regarding the initial discovery date are not provided in the breach submission, the June 13, 2025 notification date indicates that Decisely Insurance Services completed its investigation and determined the breach met HIPAA notification thresholds within a reasonable timeframe. Organizations typically discover network-based breaches through intrusion detection systems, security monitoring alerts, or reports from external security researchers. Upon discovery, Decisely Insurance Services would have been required to conduct a comprehensive forensic investigation to determine the scope of the breach, identify affected individuals, and assess what categories of information were compromised. The organization's notification to HHS suggests they completed the mandatory risk assessment required under HIPAA Breach Notification Rule 45 CFR §164.404-414, determining that the breach posed a reasonable risk of harm to affected individuals and therefore required notification.
Technical Details of the Breach
The breach involved unauthorized access to network servers and other IT infrastructure, classified as a "hacking/IT incident" rather than physical theft or loss. This categorization indicates that threat actors likely exploited vulnerabilities in the organization's network security, potentially through methods such as credential compromise, exploitation of unpatched software vulnerabilities, phishing attacks targeting employees, or other cyber attack vectors. Network server breaches typically provide attackers with broad access to stored data, potentially including multiple categories of PHI across numerous patient records. The involvement of a business associate designation suggests that Decisely Insurance Services processes, stores, or transmits PHI on behalf of covered entities such as health plans, healthcare providers, or healthcare clearinghouses. Business associates face the same HIPAA security and breach notification requirements as covered entities, and their breaches can have cascading impacts across multiple healthcare organizations that rely on their services.
Organizational Context
Decisely Insurance Services, LLC operates as an insurance services company based in Georgia, providing services that likely include insurance claims processing, eligibility verification, enrollment management, or related administrative functions. The scale of the breach—affecting over half a million individuals—indicates that the organization maintains substantial databases of patient and policyholder information, suggesting either a large regional or national service footprint. As a business associate in the healthcare ecosystem, Decisely Insurance Services would maintain PHI for multiple covered entities, meaning the breach potentially impacts patients across numerous health plans and healthcare providers. The organization's role in insurance services means it likely maintains detailed records linking individuals to their insurance coverage, claims history, and associated medical information.
Impact on Affected Individuals
The breach affected 537,603 individuals whose information was stored on Decisely Insurance Services' network servers. These individuals likely include current and former insurance policyholders, patients whose claims were processed through the organization's systems, and individuals whose health information was maintained in connection with insurance eligibility or enrollment functions. The specific categories of PHI exposed may include names, dates of birth, Social Security numbers, insurance policy numbers, medical record numbers, health plan identifiers, claims information, diagnosis codes, procedure codes, and potentially other sensitive health information. Notification of affected individuals would have been required under HIPAA regulations, with Decisely Insurance Services responsible for providing breach notification letters to all affected parties without unreasonable delay and no later than 60 calendar days after discovery of the breach.
HIPAA Compliance and Industry Context
Under the HIPAA Breach Notification Rule, organizations must notify affected individuals, the media (if more than 500 residents of a state or jurisdiction are affected), and the HHS Secretary of breaches of unsecured PHI. The submission of this breach to HHS on June 13, 2025 indicates Decisely Insurance Services' compliance with notification requirements. Network-based breaches represent a significant portion of healthcare data breaches, with the HHS Office for Civil Rights reporting that hacking incidents consistently account for the largest number of breached records in the healthcare industry. The involvement of a business associate in this breach underscores the importance of healthcare organizations' vendor management practices and the need for thorough business associate agreements that include specific security and breach notification requirements. Covered entities that rely on Decisely Insurance Services would need to assess the impact on their own operations and potentially notify their patients if the breach involved their specific patient populations. This incident serves as a reminder of the critical importance of network security controls, including firewalls, intrusion detection systems, multi-factor authentication, encryption, and regular security assessments, in protecting sensitive health information from unauthorized access.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Decisely Insurance Services, LLC Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries. Consider placing a fraud alert or credit freeze with the bureaus to prevent unauthorized credit applications. Obtain free annual credit reports at annualcreditreport.com.
Review explanation of benefits (EOB) statements and insurance claims carefully for any unauthorized services, treatments, or claims you did not receive. Contact your insurance provider immediately if you identify suspicious activity or claims you do not recognize.
Monitor financial accounts, including bank accounts and credit cards, for unauthorized transactions. Review statements regularly and set up account alerts with your financial institutions to detect suspicious activity quickly.
Consider enrolling in credit monitoring and identity theft protection services, particularly those that include monitoring of the dark web and alerts for misuse of personal information. Many insurers offer these services at no cost to affected individuals.
Change passwords for any online accounts related to your insurance coverage, healthcare providers, or financial institutions, using strong, unique passwords for each account. Enable multi-factor authentication where available.
Be cautious of unsolicited communications claiming to be from your insurance provider, healthcare providers, or financial institutions. Verify any requests for personal information by contacting the organization directly using phone numbers or websites you know to be legitimate.
Document all communications related to the breach, including notification letters, and retain them for your records. Keep detailed records of any fraudulent activity discovered and steps taken to address it.
Contact the Federal Trade Commission (FTC) at IdentityTheft.gov if you discover evidence of identity theft or fraud, and file a report to create an official record of the incident for law enforcement and creditors.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Georgia Breaches
Search all breaches reported in Georgia
Were You Affected?
Patients affected by large healthcare data breaches may be eligible for compensation through class action lawsuits.
Learn about data breach lawsuits