Highmark Inc
bd_b2b69efe74984e65 · schema v1 · pii pii-v1
Full breach record for Highmark Inc →8 incidents on fileHighmark, Inc. disclosed a cybersecurity incident occurring between December 13-15, 2022, where an employee clicked a malicious phishing link, compromising their email account. The threat actor accessed emails containing Protected Health Information (PHI) and PII of Highmark members, including names, SSNs, member IDs, claims data, and financial account numbers. Highmark shut down the mailbox, reset passwords, and implemented network blocking. Affected individuals were offered 24 months of Experian IdentityWorks.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 13, 2022
Begins
Dec 15, 2022
Discovered
Feb 10, 2023
Filed
vs. sector median
4 wks faster
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- HHS OCRbd_67a2105beb6464002023-02-10Verified
- HHS OCRbd_979c36a1443ad8f12023-02-10Verified
- Indiana State AGbd_b1db1c0f4716a2872023-02-10Verified
- South Carolina State AGbd_f08d1e5c8ae3fa0f2023-02-07 · +3dVerified
Show 5 more filings ↓Show fewer ↑up to 136d gap
- Washington State AGbd_942a588b7d88d2c32023-02-06 · +4dVerified
- Delaware State AGbd_9b2ceab0938674db2023-02-15 · +5dVerified
- California State AGbd_e3ddb304e00287ca2023-02-03 · +7dCandidate
- Maine State AGbd_f75581b2eb9ebe572023-02-03 · +7dVerified
- New Hampshire State AGbd_445a421e449e6ca32023-06-26 · +136dVerified
Filing propagation · 10 filings · 8 states
View merged incident ↗Pattern: first filing Feb 3 (CA), last Jun 26 (NH) — a 143-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.