HUMANA INC.
bd_0bfdd4ee08dd9b9d · schema v1 · pii pii-v1
Full breach record for HUMANA INC. →Between Dec 1–3, 2018, attackers conducted a credential stuffing attack against Humana's 'Humana @ Home' mobile app, verifying valid member credentials. Although no PHI was accessible via Humana @ Home, the verified credentials were reused to log into Humana's Go365 app, exposing names, dates of birth, addresses, provider names, dates of service, and types of medical service for 749 individuals (598 Humana members reported to OCR; 151 additional were employees of self-insured employer clients). Humana deactivated the Humana @ Home app and rolled out two-step authentication across its apps and websites. OCR obtained assurances that corrective actions were implemented.
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_13306157d13813b0HHS OCRfiled 2019-01-09(6d gap)Verified
- bd_ce09c0c29a2a7d98Montana State AGfiled 2019-01-03(12d gap)Candidate
- bd_4bc4a8438dd9084aHHS OCRfiled 2019-02-27(43d gap)Candidate
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jan 15, 2019
- Raw hash
- 7ffaa8ea6086a8f2840ac5329fdfd6fd8e63641e7fc7237b57c172e0d6fbe0bf
Source filing
Reporting entity
- Name
- HUMANA INC.norm: humana
- Domain
- humana.com
Victim entity
- Name
- HUMANA INC.norm: humana
- Domain
- humana.com
- Industry
- Health Plan
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- Jan 15, 2019
- Affected individuals
- 598
- Data types
- IDENTITY_BASICHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1110.004 Credential Stuffing
- Threat actor
- External
- Regulator citations
- HHS OCR breach reportOCR obtained assurances of corrective actions
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: Jan 15, 2019— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.