KYHackingHealthcareFinancial ServicesHealthcareStolen CredentialsBusiness Associate (HIPAA)Customer Data InvolvedData ExfiltratedHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTHighResolved
HUMANA INC.
bd_13306157d13813b0 · schema v1 · pii pii-v1
Full breach record for HUMANA INC. →Humana Inc. reported to HHS on 2019-01-09 an Unauthorized Access/Disclosure affecting 1,211 members. On August 7, 2018, an unauthorized third party used stolen credentials belonging to employees of a business associate (BA) to access the BA's computer network containing PHI. Exposed data included names, dates of birth, insurance policy numbers, and last four SSN digits. The BA contacted the FBI; Humana notified HHS, affected individuals, and the media. Corrective actions were confirmed by OCR. Breached information located on Other system.
HIPAA clock✓ HHS notified22 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_0bfdd4ee08dd9b9dHHS OCRfiled 2019-01-15(6d gap)Verified
- bd_ce09c0c29a2a7d98Montana State AGfiled 2019-01-03(6d gap)Candidate
- bd_4bc4a8438dd9084aHHS OCRfiled 2019-02-27(49d gap)Candidate
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jan 9, 2019
- Raw hash
- 896b82fdfe0f004c09cf7c2b3dc298b017b98c6a500642552854f3e3cc318471
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- HUMANA INC.norm: humana
- Domain
- humana.com
- Industry
- Insurance — Health
Victim entity
- Name
- HUMANA INC.norm: humana
- Domain
- humana.com
- Industry
- Insurance — Health
- Industry
- Healthcaresource defaultFinancial Servicesllm
Incident
- Discovered
- Aug 7, 2018
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 1,211
- Data types
- HEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- HHS OCR — obtained assurances of corrective actions; FBI notified by business associate
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 22 weeks(155 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Aug 7, 2018→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.