MisusePrivilege AbuseData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedSupply Chain (3P Vendor)IDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASICPHIMediumContained
HUMANA INC.
bd_8b264034a04f1ce4 · schema v1 · pii pii-v1
Full breach record for HUMANA INC. →Humana Inc. notified South Carolina residents of a privacy incident involving a subcontractor employee (Visionary, working for Cotiviti) who inappropriately used authorized access to disclose member medical records to unauthorized individuals for a personal coding business. The incident occurred between October 12, 2020, and December 16, 2020. Affected data included SSNs, names, DOBs, addresses, and PHI. Humana disabled access, launched an investigation, hired cybersecurity firms, and provided two years of free credit monitoring via Equifax.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_847891d7144c0211Maine State AGfiled 2021-02-23Verified
- bd_bc946186ec458638Washington State AGfiled 2021-02-23Verified
- bd_f467455aa0de3335HHS OCRfiled 2021-02-22(1d gap)Verified
- bd_3ed96e6747f3c116Montana State AGfiled 2021-02-25(2d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 13d gap
- bd_04839022a22e376eCalifornia State AGfiled 2021-03-08(13d gap)Verified
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Business%20Resources%20Laws/Related%20Laws/Breaches/2021/Humana.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 23, 2021
- Raw hash
- 553237cad3c2b4b668e1d0d92fd049477977817cc3c8c60c1fcae65179cfa286
Reporting entity
- Name
- HUMANA INC.norm: humana
- Domain
- humana.com
Victim entity
- Name
- HUMANA INC.norm: humana
- Domain
- humana.com
Incident
- Discovered
- Dec 16, 2020
- Materiality determined
- —
- Notification sent
- Feb 25, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASICPHI
- Attack vector
- Insider
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- InternalSecondary
- Initial access
- insider_action
Compliance
- Time to disclose
- 10 weeks(69 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.