Highmark Inc
bd_9b2ceab0938674db · schema v1 · pii pii-v1
Full breach record for Highmark Inc →Highmark Health disclosed a cybersecurity incident discovered on December 15, 2022, involving a phishing email sent to an employee. The employee's email account was compromised between December 13 and 15, 2022. The threat actor accessed emails containing Protected Health Information (PHI) of Highmark members. Affected data includes names, SSNs, member IDs, claims/treatment info, financial account numbers, passwords, addresses, DOBs, and phone numbers. Highmark shut down the mailbox, reset passwords, implemented network blocking, and provided 24 months of Experian IdentityWorks.
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_b2b69efe74984e65Delaware State AGfiled 2023-02-10(5d gap)Verified
- bd_942a588b7d88d2c3Washington State AGfiled 2023-02-06(9d gap)Verified
- bd_e3ddb304e00287caCalifornia State AGfiled 2023-02-03(12d gap)Candidate
- bd_f75581b2eb9ebe57Maine State AGfiled 2023-02-03(12d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 131d gap
- bd_445a421e449e6ca3New Hampshire State AGfiled 2023-06-26(131d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/04/DE-Highmark.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 15, 2023
- Raw hash
- 587f9be95f19e931686fdceb89935b5a90934048d7b16cffd564e9d486c899bd
Reporting entity
- Name
- Highmark Incnorm: highmark
- Domain
- highmark.com
Victim entity
- Name
- Highmark Incnorm: highmark
- Domain
- highmark.com
Incident
- Discovered
- Dec 15, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 9 weeks(62 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.