MisusePrivilege AbuseCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTPHIMediumResolved
UnitedHealth Group Incorporated
bd_05bd65f244917bed · schema v1 · pii pii-v1
Full breach record for UnitedHealth Group Incorporated →UnitedHealth Group health plan single affiliated covered entity experienced unauthorized internal access to a database between June 28 and December 12, 2011. Discovered on January 30, 2012, the incident exposed member PII (name, SSN, DOB, address, Medicare ID). The company investigated, reported to law enforcement, and offered one year of Equifax credit monitoring. Remediation included reinforcing employee policies and evaluating additional safeguards.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-22860
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 30, 2012
- Raw hash
- b33b4eddacd3968eb4e1e97ef53eeb512e823a1f8200cae0a4dd4a4e95d9cc90
Reporting entity
- Name
- UnitedHealth Group Incorporatednorm: unitedhealth group
- Domain
- unitedhealthgroup.com
Victim entity
- Name
- UnitedHealth Group Incorporatednorm: unitedhealth group
- Domain
- unitedhealthgroup.com
Incident
- Discovered
- Jan 30, 2012
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPHI
- Attack vector
- Insider
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- Internal
- Regulator citations
- reported the incident to law enforcement authorities
- Initial access
- insider_action
Compliance
- Time to disclose
- 9 weeks(60 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.