OneTouchPoint, Inc. Data Breach
OneTouchPoint Network Server Breach Affects 4.1M Individuals
What happened in the OneTouchPoint, Inc. data breach?
The OneTouchPoint, Inc. data breach was reported on July 27, 2022 and affected 4,112,892 individuals. The breach type was Hacking/IT Incident involving Network Server. This breach occurred in Wisconsin. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
OneTouchPoint, Inc. Breach Details
OneTouchPoint, Inc. Data Breach Report
Opening Summary
OneTouchPoint, Inc., a healthcare data management and business associate organization based in Wisconsin, experienced a significant data breach involving unauthorized access to its network server infrastructure. The breach was discovered and reported to the U.S. Department of Health and Human Services on July 27, 2022. The incident resulted in the exposure of protected health information (PHI) belonging to approximately 4.1 million individuals across multiple healthcare entities that utilize OneTouchPoint's services. This breach represents one of the largest healthcare data compromises reported in 2022 and underscores the critical vulnerabilities that exist in third-party healthcare IT systems and business associate networks.
Company Response and Investigation Timeline
Upon discovery of the unauthorized access to its network server, OneTouchPoint initiated an immediate investigation to determine the scope and nature of the breach. The organization worked to identify which patient records had been accessed and began the process of notifying affected individuals and covered entities in accordance with HIPAA Breach Notification Rule requirements. The submission date of July 27, 2022, indicates that the organization met the regulatory requirement to notify HHS within 60 days of discovery. OneTouchPoint coordinated with its client healthcare organizations to ensure comprehensive notification of affected patients and implemented remediation measures to secure its network infrastructure and prevent future unauthorized access.
Technical Details of the Breach
The breach occurred through unauthorized access to OneTouchPoint's network server, which typically indicates a compromise of the organization's IT infrastructure rather than a physical theft of devices or documents. Network server breaches of this magnitude commonly result from vulnerabilities such as unpatched software, weak authentication mechanisms, compromised credentials, or exploitation of known security weaknesses. The fact that this breach affected a business associate—an organization that handles PHI on behalf of covered entities—suggests that the attacker gained access to centralized systems containing data from multiple healthcare providers. The scale of the breach (over 4 million individuals) indicates that the compromised server likely contained consolidated patient records from numerous healthcare organizations that contracted OneTouchPoint's services for billing, claims processing, data management, or other administrative functions.
Organizational Context and Operations
OneTouchPoint, Inc. operates as a healthcare business associate, providing critical data management, billing, and administrative services to healthcare providers throughout Wisconsin and potentially beyond. As a business associate, the organization is subject to HIPAA regulations and is contractually obligated to maintain the security and privacy of PHI entrusted to it by covered entities such as hospitals, physician practices, and other healthcare organizations. The scope of OneTouchPoint's operations—serving enough healthcare entities to accumulate records on 4.1 million individuals—indicates a substantial regional or national presence in healthcare IT services. Business associates like OneTouchPoint are frequent targets for cybercriminals because they serve as centralized repositories of patient data from multiple healthcare organizations, making a single successful breach potentially catastrophic in terms of the number of individuals affected.
Impact on Affected Individuals
Approximately 4,112,892 individuals had their protected health information potentially exposed through this breach. The specific types of data exposed likely include names, dates of birth, Social Security numbers, medical record numbers, insurance information, and clinical details—though the exact data elements compromised would depend on what information was stored on the breached network server. Patients affected by this breach may have received notification letters from their respective healthcare providers, as covered entities are required to notify patients of breaches affecting their PHI. The notification process for a breach of this magnitude typically involves coordination between OneTouchPoint and dozens or potentially hundreds of healthcare organizations, each responsible for notifying their own patients. Individuals affected should have received information about the breach, the types of data exposed, steps they can take to protect themselves, and contact information for credit monitoring or identity theft protection services that may have been offered.
HIPAA Compliance and Industry Context
Under the HIPAA Breach Notification Rule, covered entities and business associates must notify affected individuals of breaches of unsecured PHI without unreasonable delay and no later than 60 calendar days after discovery of the breach. OneTouchPoint's July 27, 2022 submission date to HHS indicates compliance with this timeline. Network server breaches affecting business associates represent a significant category of healthcare data breaches, accounting for a substantial portion of large-scale incidents in recent years. The healthcare industry has experienced an increasing number of sophisticated cyberattacks targeting business associates, as these organizations often manage sensitive data for multiple covered entities and may have fewer resources dedicated to cybersecurity compared to large hospital systems. The 4.1 million individuals affected by this breach places it among the largest healthcare data breaches reported to HHS, highlighting the critical importance of strong security measures for organizations handling centralized patient data repositories.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the OneTouchPoint, Inc. Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for fraudulent accounts or inquiries. Consider placing a fraud alert or credit freeze with the bureaus to prevent unauthorized credit applications.
Review explanation of benefits (EOB) statements and medical bills carefully for any services you did not receive. Contact your healthcare providers and insurance company immediately if you identify suspicious medical charges or claims.
Change passwords for all online healthcare accounts, insurance portals, and financial accounts, using strong, unique passwords. Enable multi-factor authentication where available.
Consider enrolling in identity theft protection or credit monitoring services if offered by OneTouchPoint or your healthcare provider. These services typically provide monitoring, alerts, and recovery assistance if fraud occurs.
Be vigilant against phishing emails and phone calls claiming to be from healthcare providers or financial institutions. Do not click links or provide information in response to unsolicited communications.
File a report with the Federal Trade Commission (FTC) at IdentityTheft.gov if you believe your information has been misused, and consider filing a police report for documentation purposes.
Contact your healthcare providers to verify that your medical records are accurate and have not been altered or accessed inappropriately.
Monitor Social Security earnings statements and tax records for signs of identity theft or fraudulent use of your Social Security number.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Wisconsin Breaches
Search all breaches reported in Wisconsin
Were You Affected?
Patients affected by large healthcare data breaches may be eligible for compensation through class action lawsuits.
Learn about data breach lawsuits