AETNA INC.
bd_e0a09a5e5c8494c8 · schema v1 · pii pii-v1
Full breach record for AETNA INC. →Aetna Inc. (CT, Health Plan) reported to HHS OCR on 2017-06-20 an Unauthorized Access/Disclosure affecting 5,002 individuals. On April 27, 2017, two web services displaying plan documents allowed access without login credentials and were indexed by internet search engines, exposing names, insurance IDs, claim payment amounts, procedure codes, and dates of service. Separately, envelope mailings in July and September 2017 inadvertently disclosed HIV medication and atrial fibrillation study participation to additional members. OCR settled with Aetna for $1,000,000 plus a corrective action plan. Breached information located on Network Server.
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_2b581417c63b869aMontana State AGfiled 2017-06-21(1d gap)Candidate
- bd_198e8a847472d62fOregon State AGfiled 2017-07-10(20d gap)Verified
- bd_ac8d5720b2156302HHS OCRfiled 2017-08-29(70d gap)Verified
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jun 20, 2017
- Raw hash
- bf00332aead8ef7d2f961ad2b46ff9176671ff3b9d526d5aad079e20007b30ff
Source filing
Reporting entity
- Name
- AETNA INC.norm: aetna
- Domain
- aetna.com
- Industry
- Insurance — Health
Victim entity
- Name
- AETNA INC.norm: aetna
- Domain
- aetna.com
- Industry
- Insurance — Health
- Industry
- Healthcaresource defaultFinancial Servicesllm
Incident
- Discovered
- Apr 27, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 5,002
- Data types
- IDENTITY_BASICHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1530 Data from Cloud Storage
- Regulator citations
- HHS OCR — $1,000,000 settlement payment and corrective action plan for potential violations of HIPAA Privacy and Security Rules
Compliance
- Time to disclose
- 8 weeks(54 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Apr 27, 2017→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.