Highmark Inc
bd_e3ddb304e00287ca · schema v1 · pii pii-v1
Full breach record for Highmark Inc →8 incidents on fileHighmark disclosed a cyber security incident where an employee clicked a malicious email link, leading to email account compromise between Dec 13-15, 2022. Protected health information (PHI), including names, SSNs (for some), and treatment info, was potentially accessed. Highmark shut down the mailbox, reset passwords, and offered 24 months of Experian IdentityWorks.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 13, 2022
Begins
Dec 15, 2022
Discovered
Feb 3, 2023
Filed
vs. sector median
5 wks faster
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- Maine State AGbd_f75581b2eb9ebe572023-02-03Verified
- Washington State AGbd_942a588b7d88d2c32023-02-06 · +3dVerified
- South Carolina State AGbd_f08d1e5c8ae3fa0f2023-02-07 · +4dVerified
- HHS OCRbd_67a2105beb6464002023-02-10 · +7dVerified
Show 5 more filings ↓Show fewer ↑up to 143d gap
- HHS OCRbd_979c36a1443ad8f12023-02-10 · +7dVerified
- Indiana State AGbd_b1db1c0f4716a2872023-02-10 · +7dVerified
- Delaware State AGbd_b2b69efe74984e652023-02-10 · +7dVerified
- Delaware State AGbd_9b2ceab0938674db2023-02-15 · +12dVerified
- New Hampshire State AGbd_445a421e449e6ca32023-06-26 · +143dVerified
Filing propagation · 10 filings · 8 states
View merged incident ↗Pattern: first filing Feb 3 (ME), last Jun 26 (NH) — a 143-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.