Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedMulti-Stage ChainPHIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Highmark Inc
bd_445a421e449e6ca3 · schema v1 · pii pii-v1
Full breach record for Highmark Inc →Highmark Health reported a phishing incident where an employee's email account was compromised between Dec 13-15, 2022. The attacker accessed emails containing PHI and PII (name, SSN) of 696 NH residents. Highmark shut down the mailbox, reset passwords, and engaged forensic consultants. Notices were sent to affected individuals and regulators on Feb 13, 2023.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_9b2ceab0938674dbDelaware State AGfiled 2023-02-15(131d gap)Verified
- bd_b2b69efe74984e65Delaware State AGfiled 2023-02-10(136d gap)Verified
- bd_942a588b7d88d2c3Washington State AGfiled 2023-02-06(140d gap)Verified
- bd_e3ddb304e00287caCalifornia State AGfiled 2023-02-03(143d gap)Candidate
Show 1 more filing ↓Show fewer ↑up to 143d gap
- bd_f75581b2eb9ebe57Maine State AGfiled 2023-02-03(143d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/highmark-health-20230626.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 26, 2023
- Raw hash
- a9f6b6743525dd0d26e93dbb842fb5f8604f8ba94b38754da877cc6a428f49c1
Reporting entity
- Name
- Highmark Incnorm: highmark
- Domain
- highmark.com
Victim entity
- Name
- Highmark Incnorm: highmark
- Domain
- highmark.com
Incident
- Discovered
- Dec 15, 2022
- Materiality determined
- —
- Notification sent
- Feb 13, 2023
- Affected individuals
- 696
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- issued appropriate regulatory notices to the Department of Health and Humans Services (HHS), state attorney general, and other regulatory agencies
- Initial access
- phishing_link
Compliance
- Time to disclose
- 28 weeks(193 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.