MisuseData MishandlingData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICHEALTH_BASICLowContained
HUMANA INC.
bd_04839022a22e376e · schema v1 · pii pii-v1
Full breach record for HUMANA INC. →Humana Inc reported a privacy incident involving unauthorized access to member medical records by a subcontractor employee. The breach occurred between October 12, 2020, and December 16, 2020. The employee disclosed information, including names and dates of birth, to unauthorized individuals via a personal Google Drive account for personal coding training purposes. Humana engaged cybersecurity firms, disabled access, and provided two years of free credit monitoring to affected individuals.
California clockDiscovered Dec 16, 2020 → Notified Mar 8, 202182d ✗ CA 60-day late12 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_3ed96e6747f3c116Montana State AGfiled 2021-02-25(11d gap)Verified
- bd_847891d7144c0211Maine State AGfiled 2021-02-23(13d gap)Verified
- bd_8b264034a04f1ce4South Carolina State AGfiled 2021-02-23(13d gap)Verified
- bd_bc946186ec458638Washington State AGfiled 2021-02-23(13d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 14d gap
- bd_f467455aa0de3335HHS OCRfiled 2021-02-22(14d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-538937
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 8, 2021
- Raw hash
- b44168ec6630032264cc62a3ba6af1499cb10a7335dc82ef463275fa3fc4d7eb
Reporting entity
- Name
- HUMANA INC.norm: humana
- Domain
- humana.com
Victim entity
- Name
- HUMANA INC.norm: humana
- Domain
- humana.com
Incident
- Discovered
- Dec 16, 2020
- Materiality determined
- —
- Notification sent
- Mar 8, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASIC
- Attack vector
- Insider
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- InternalSecondary
- Initial access
- insider_action
Compliance
- Time to disclose
- 12 weeks(82 days from discovery to filing)
- Compliance flags
- CA 60-day late · 82d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 16, 2020→ Notified: Mar 8, 202182d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.