METROPOLITAN LIFE INSURANCE CO
bd_16c4dd386abd199f · schema v1 · pii pii-v1
Full breach record for METROPOLITAN LIFE INSURANCE CO →Metropolitan Life Insurance Company (MetLife) reported to HHS on 2017-07-19 an Unauthorized Access/Disclosure affecting 4,220 individuals. An unauthorized individual used an external phishing email to harvest account credentials from MetLife customers and non-customers, gaining access to ~4,420 online customer accounts. PHI exposed included names, addresses, health policy numbers, and account/authentication information. OCR ultimately determined the incident did not constitute a HIPAA breach as MetLife's own systems were not compromised. MetLife notified affected individuals and provided free credit monitoring. Location of breached information: Other.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jul 19, 2017
- Raw hash
- ca2b75186f36742a77e5e164b365af5da09d9dc770d91797dd79beea85df6500
Source filing
Reporting entity
- Name
- METROPOLITAN LIFE INSURANCE COnorm: metropolitan life insurance
- Domain
- metlife.com
- Industry
- Insurance — Health
Victim entity
- Name
- METROPOLITAN LIFE INSURANCE COnorm: metropolitan life insurance
- Domain
- metlife.com
- Industry
- Insurance — Health
- Industry
- Healthcaresource defaultFinancial Servicesllm
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 4,220
- Data types
- IDENTITY_BASICHEALTH_BASICFINANCIAL_ACCOUNTAUTHENTICATION
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1566 PhishingT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- HHS OCR investigation; OCR determined incident did not constitute a breach under HIPAA as MetLife's own systems were not compromised.
- Initial access
- phishing_link
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.