HUMANA INC.
bd_afa98d3f40978317 · schema v1 · pii pii-v1
Full breach record for HUMANA INC. →Humana Inc. (Health Plan, KY) reported to HHS OCR on 2019-06-03 an Unauthorized Access/Disclosure affecting 863 individuals. From March 15 to May 1, 2019, a programming error in Humana's Go365 mobile app allowed participants to view other participants' PHI, including names, addresses, email addresses, identification numbers, biometric screening data, and other wellness information stored on a Network Server. 357 affected individuals were Humana members; 486 were employees of 179 self-insured employer clients. Humana deployed two app updates to fix the error and initiated ongoing monitoring. No business associate was involved.
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_687bdb89bbe36c1dMontana State AGfiled 2019-06-07(4d gap)Candidate
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jun 3, 2019
- Raw hash
- 70876603b6be3ffe331cbf7734edf09ec2045e98b4e29f92bb67a0842ff0ebc6
Source filing
Reporting entity
- Name
- HUMANA INC.norm: humana
- Domain
- humana.com
- Industry
- Insurance — Health
Victim entity
- Name
- HUMANA INC.norm: humana
- Domain
- humana.com
- Industry
- Insurance — Health
- Industry
- Healthcaresource defaultFinancial Servicesllm
Incident
- Discovered
- May 1, 2019
- Materiality determined
- —
- Notification sent
- Jun 3, 2019
- Affected individuals
- 863
- Data types
- HEALTH_BASICIDENTITY_BASICBIOMETRICMETADATA
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Regulator citations
- HHS OCR notified; OCR obtained assurances that Humana implemented corrective actions
Compliance
- Time to disclose
- 5 weeks(33 days from discovery to filing)
- Compliance flags
- HIPAA 60-day OK · 33dHHS notified · 33d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: May 1, 2019→ Notified: Jun 3, 201933d 60 days HIPAA 60-day OK HIPAA Discovered: May 1, 2019→ Notified: Jun 3, 201933d regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.