Highmark Inc
bd_445a421e449e6ca3 · schema v1 · pii pii-v1
Full breach record for Highmark Inc →8 incidents on fileHighmark Health reported a phishing incident where an employee's email account was compromised between Dec 13-15, 2022. The attacker accessed emails containing PHI and PII (name, SSN) of 696 NH residents. Highmark shut down the mailbox, reset passwords, and engaged forensic consultants. Notices were sent to affected individuals and regulators on Feb 13, 2023.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 13, 2022
Begins
Dec 15, 2022
Discovered
Jun 26, 2023
Filed
vs. sector median
+15 wks slower
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- Delaware State AGbd_9b2ceab0938674db2023-02-15 · +131dVerified
- HHS OCRbd_67a2105beb6464002023-02-10 · +136dVerified
- HHS OCRbd_979c36a1443ad8f12023-02-10 · +136dVerified
- Indiana State AGbd_b1db1c0f4716a2872023-02-10 · +136dVerified
Show 5 more filings ↓Show fewer ↑up to 143d gap
- Delaware State AGbd_b2b69efe74984e652023-02-10 · +136dVerified
- South Carolina State AGbd_f08d1e5c8ae3fa0f2023-02-07 · +139dVerified
- Washington State AGbd_942a588b7d88d2c32023-02-06 · +140dVerified
- California State AGbd_e3ddb304e00287ca2023-02-03 · +143dCandidate
- Maine State AGbd_f75581b2eb9ebe572023-02-03 · +143dVerified
Filing propagation · 10 filings · 8 states
View merged incident ↗Pattern: first filing Feb 3 (CA), last Jun 26 (NH) — a 143-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.