HackingStolen CredentialsCustomer Data InvolvedDelayed DiscoveryPHIIDENTITY_BASICHEALTH_BASICLowContained
UNITEDHEALTHCARE INSURANCE COMPANY
bd_e9287cbe0a2d6519 · schema v1 · pii pii-v1
Full breach record for UNITEDHEALTHCARE INSURANCE COMPANY →UnitedHealthcare discovered unauthorized access to its broker portal on December 29, 2022. The incident occurred between December 1, 2022, and January 25, 2023. An unauthorized party accessed member health information, including names, member IDs, and plan details, while attempting to divert funds. Social Security numbers and financial account information were not involved. UnitedHealthcare disabled affected accounts and implemented additional security controls.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_eaecdba95f10cfd7Oregon State AGfiled 2023-08-31Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-572712
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 31, 2023
- Raw hash
- ca46c0810549bf323cb8ae71a6f3f5e625e23120a2cd04be989988b7cd6261fd
Reporting entity
- Name
- UNITEDHEALTHCARE INSURANCE COMPANYnorm: unitedhealthcare insurance
- Domain
- uhc.com
Victim entity
- Name
- UNITEDHEALTHCARE INSURANCE COMPANYnorm: unitedhealthcare insurance
- Domain
- uhc.com
Incident
- Discovered
- Dec 29, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 35 weeks(245 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.