CareFirst Blue Cross Blue Shield
bd_a170a3c85daf2049 · schema v1 · pii pii-v1
Full breach record for CareFirst Blue Cross Blue Shield →5 incidents on fileCareFirst BlueCross BlueShield notified the NH AG of a cyberattack discovered April 21, 2015, involving unauthorized access to a broker database on June 19, 2014. Attackers potentially acquired broker names, SSNs, and usernames. 1.1 million individuals affected nationwide; 7 NH residents. No passwords or financial/medical data accessed. Credit monitoring offered.
J jump to incidentP pin to compareR raw source
Incident timeline
Jun 19, 2014
Begins
Apr 21, 2015
Discovered
May 20, 2015
Filed
vs. sector median
8 wks faster
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- HHS OCRbd_693df094849cb1ad2015-05-20Verified
- California State AGbd_d3530dd6d928135a2015-05-20Verified
Filing propagation · 3 filings · 3 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.