HUMANA INC.
bd_f547a5594bd4d970 · schema v1 · pii pii-v1
Full breach record for HUMANA INC. →40 incidents on fileHumana Inc. (KY, Health Plan) reported to HHS on 2021-11-09 a Hacking/IT Incident affecting 1,823 individuals. A business associate experienced a ransomware attack that encrypted ePHI stored on a network server. Exposed data included names, addresses, dates of birth, Social Security numbers, diagnoses and medical conditions, medications prescribed, and other treatment information. The BA notified affected individuals and media, and provided complimentary credit monitoring. OCR provided technical assistance on the HIPAA Breach Notification Rule.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Nov 9, 2021
Filed
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Indiana State AGbd_a1260383936f6b4c2021-11-12 · +3dVerified
- HHS OCRbd_af457bc18d369cb02021-11-04 · +5dVerified
Filing propagation · 3 filings · 2 states
View merged incident ↗Pattern: first filing Nov 4 (KY), last Nov 12 (IN) — a 8-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.