Foundation Health Partners Data Breach
Foundation Health Partners Paper Records Breach Affects 523 in Alaska
What happened in the Foundation Health Partners data breach?
The Foundation Health Partners data breach was reported on January 9, 2026 and affected 523 individuals. The breach type was Unauthorized Access/Disclosure involving Paper/Films. This breach occurred in Alaska. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Foundation Health Partners Breach Details
Foundation Health Partners Data Breach Report
Incident Overview
Foundation Health Partners, a healthcare organization operating in Alaska, experienced an unauthorized access and disclosure incident involving paper-based medical records and films on an unspecified date prior to the January 9, 2026 submission to the HHS Office for Civil Rights. The breach resulted in the potential exposure of protected health information (PHI) belonging to 523 individuals. This incident represents a significant departure from digital security breaches, as the compromised materials were physical documents and imaging films rather than electronic data systems, highlighting the continued vulnerability of paper-based healthcare record storage and management practices.
Discovery and Response Timeline
The specific date of discovery and the mechanism by which Foundation Health Partners identified the unauthorized access have not been detailed in available breach notification records. However, the organization's submission to the HHS OCR on January 9, 2026, indicates that a formal investigation was conducted and documented prior to regulatory notification. Standard HIPAA breach notification protocols require covered entities to notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery of a breach. The organization's notification timeline and specific investigative findings remain part of the formal breach documentation submitted to regulatory authorities. Foundation Health Partners would have been required to conduct a risk assessment to determine whether the unauthorized access created a reasonable likelihood of harm to the affected individuals, which would trigger mandatory notification requirements.
Breach Mechanism and Operational Details
The breach involved unauthorized access to and disclosure of paper records and films, which typically indicates physical security vulnerabilities rather than cybersecurity failures. Paper-based medical records and imaging films may be compromised through several common vectors: unsecured storage areas, inadequate access controls to medical records departments, theft of physical documents, loss of records during transport or storage transitions, or unauthorized employee access to filing systems. The location designation of "Paper/Films" suggests that the breach did not involve electronic health record (EHR) systems, network servers, or cloud-based storage platforms. This type of incident often reflects gaps in physical security infrastructure, such as unlocked file cabinets, unsupervised storage rooms, or inadequate chain-of-custody procedures for sensitive documents. The fact that no business associate was involved indicates that the breach occurred within Foundation Health Partners' own facilities or under their direct operational control, rather than through a third-party vendor or service provider.
Organizational Context
Foundation Health Partners operates as a healthcare provider organization in Alaska, serving patients across the state. The organization's operations encompass clinical services that generate and maintain both electronic and paper-based medical records. The involvement of paper records and imaging films in this breach suggests that Foundation Health Partners maintains hybrid record-keeping systems, combining digital and physical documentation—a common practice in healthcare organizations of various sizes. Alaska's geographic characteristics, including vast distances between communities and limited healthcare infrastructure in rural areas, may influence how the organization manages records across multiple locations. The organization's size, as indicated by the 523 affected individuals, suggests a regional healthcare provider rather than a single-facility clinic, though the exact scope of operations is not specified in breach notification data.
Patient Impact and Affected Population
A total of 523 individuals had their protected health information potentially exposed through this breach. These patients represent a discrete population whose medical records and/or imaging films were subject to unauthorized access or disclosure. The affected individuals would have been notified of the breach in accordance with HIPAA's Breach Notification Rule, which requires covered entities to provide written notice to each individual whose unsecured PHI has been, or is reasonably believed by the covered entity to have been, accessed, acquired, used, or disclosed as a result of the breach. The notification would have included information about the nature of the breach, the types of information involved, steps the organization is taking to investigate and mitigate the breach, and recommended actions patients should take to protect themselves. Foundation Health Partners would also have been required to notify prominent media outlets and the HHS Secretary, given the breach notification requirements under 45 CFR §164.404-414.
Data Exposure and Information Types
Personal Information Involved
While the specific data elements contained in the compromised paper records and films are not itemized in the breach submission, paper-based medical records typically contain multiple categories of protected health information, including:
- Patient names and contact information (addresses, telephone numbers)
- Medical record numbers and patient identification numbers
- Dates of birth and ages
- Social Security numbers (commonly used as patient identifiers in healthcare settings)
- Insurance information and policy numbers
- Diagnoses and medical history
- Treatment plans and clinical notes
- Medication lists and pharmacy information
- Laboratory and imaging results
- Imaging films and radiological studies
- Emergency contact information
- Employment and employer information
- Healthcare provider names and facility information
The inclusion of "films" in the breach description indicates that radiological imaging materials were compromised, which may contain patient identifiers and sensitive clinical information about conditions such as fractures, tumors, or other medical findings visible on imaging studies.
Risks to Affected Patients
The unauthorized access to paper records and films creates several categories of risk for affected individuals:
Identity Theft and Fraud Risk: If Social Security numbers, dates of birth, and other personally identifiable information were exposed, patients face elevated risk of identity theft, financial fraud, and fraudulent account creation. Healthcare-related identity theft is particularly concerning because stolen medical information can be used to obtain medical services, prescription medications, or medical devices under the victim's name and insurance.
Medical Identity Theft: Criminals may use exposed medical information to fraudulently obtain healthcare services, prescription medications, or medical equipment, potentially resulting in unauthorized charges to the patient's insurance and creation of false medical records that could interfere with legitimate future care.
Insurance Fraud: Exposed insurance information could be used to file fraudulent claims or obtain unauthorized coverage.
Privacy Violation and Stigma: Unauthorized disclosure of sensitive medical information—particularly regarding conditions such as mental health diagnoses, HIV status, substance use disorders, or reproductive health—could result in privacy violations and potential social or employment discrimination if the information is disclosed to unauthorized parties.
Reputational Harm: Patients may experience emotional distress and loss of trust in the healthcare organization as a result of the breach.
Ongoing Vulnerability: Patients whose information was exposed through physical document theft or loss may face continued risk if the documents remain in unauthorized possession and are subsequently used for fraudulent purposes.
Recommended Actions for Patients
- Monitor Credit Reports: Obtain free credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) through AnnualCreditReport.com and review for unauthorized accounts or inquiries. Consider placing a fraud alert or credit freeze with the bureaus to prevent unauthorized account creation.
- Monitor Medical Records and Insurance Statements: Request copies of medical records from Foundation Health Partners and review for unauthorized access or treatment. Carefully review explanation of benefits (EOB) statements from your health insurance for claims you did not authorize.
- Monitor Financial Accounts: Review bank statements, credit card statements, and other financial accounts regularly for unauthorized transactions. Set up account alerts with your financial institutions to notify you of unusual activity.
- Consider Identity Theft Protection Services: Evaluate enrollment in credit monitoring or identity theft protection services, which may be offered by Foundation Health Partners as part of their breach response. These services can provide early warning of fraudulent activity and assistance with remediation if identity theft occurs.
HIPAA Compliance and Regulatory Context
This breach represents a violation of the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule (45 CFR §164.400 et seq.), which requires covered entities to implement administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of electronic protected health information. The involvement of paper records indicates a failure in physical safeguards, specifically the requirement under 45 CFR §164.310(b) to "implement physical access controls to limit unauthorized access to facilities that house electronic information systems and related equipment." While this regulation specifically addresses electronic systems, HIPAA's broader Privacy Rule requires protection of all PHI, regardless of format.
Paper-based breaches, while less common in recent years due to increased digitization of healthcare records, continue to represent a significant vulnerability in healthcare security. The breach notification requirement under 45 CFR §164.404 mandates that covered entities notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery of a breach. Foundation Health Partners' January 9, 2026 submission date indicates compliance with OCR notification requirements, though the actual notification to patients would have occurred earlier in the 60-day window.
Industry Context and Similar Incidents
Physical document breaches remain a persistent challenge in healthcare, despite the industry's shift toward electronic health records. According to HHS OCR breach statistics, paper-based incidents continue to represent a meaningful percentage of reported healthcare breaches, often involving theft, loss, or unauthorized access to medical records stored in physical locations. These incidents frequently result from inadequate physical security controls, insufficient staff training on document handling procedures, and gaps in access management for medical records departments.
The 523-individual impact of this breach places it within the range of typical paper-based incidents, which often affect smaller populations than large-scale cybersecurity breaches. However, the sensitivity of medical information contained in paper records means that even smaller-scale breaches can create significant risk for affected individuals. Healthcare organizations are increasingly implementing hybrid security approaches that combine physical security improvements (such as locked storage, surveillance systems, and access logging) with digital record management to reduce reliance on paper-based systems and associated vulnerabilities.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Foundation Health Partners Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) through AnnualCreditReport.com and consider placing a fraud alert or credit freeze to prevent unauthorized account creation
Review medical records from Foundation Health Partners and monitor explanation of benefits (EOB) statements from your health insurance for unauthorized claims or treatment
Monitor bank statements, credit card statements, and financial accounts regularly for unauthorized transactions and set up account alerts with financial institutions
Consider enrolling in credit monitoring or identity theft protection services, which may be offered by Foundation Health Partners as part of their breach response
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Alaska Breaches
Search all breaches reported in Alaska