Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedPHIIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASICFINANCIALMediumContained
Highmark Inc
bd_e3ddb304e00287ca · schema v1 · pii pii-v1
Full breach record for Highmark Inc →Highmark disclosed a cyber security incident where an employee clicked a malicious email link, leading to email account compromise between Dec 13-15, 2022. Protected health information (PHI), including names, SSNs (for some), and treatment info, was potentially accessed. Highmark shut down the mailbox, reset passwords, and offered 24 months of Experian IdentityWorks.
California clockDiscovered Dec 15, 2022 → Notified Feb 13, 202360d ✓ CA 60-day OK7 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_f75581b2eb9ebe57Maine State AGfiled 2023-02-03Verified
- bd_942a588b7d88d2c3Washington State AGfiled 2023-02-06(3d gap)Verified
- bd_b2b69efe74984e65Delaware State AGfiled 2023-02-10(7d gap)Verified
- bd_9b2ceab0938674dbDelaware State AGfiled 2023-02-15(12d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 143d gap
- bd_445a421e449e6ca3New Hampshire State AGfiled 2023-06-26(143d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-562696
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 3, 2023
- Raw hash
- 79a59ccbd5086738db70b1d4780875567696db0f598e20c94e89ded4710ecdfd
Reporting entity
- Name
- Highmark Incnorm: highmark
- Domain
- highmark.com
Victim entity
- Name
- Highmark Incnorm: highmark
- Domain
- highmark.com
Incident
- Discovered
- Dec 15, 2022
- Materiality determined
- —
- Notification sent
- Feb 13, 2023
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASICFINANCIAL
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 7 weeks(50 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 60d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 15, 2022→ Notified: Feb 13, 202360d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.