AETNA INC.
ent_019e07ca49ec446a0ba664c4140f7cee
Disclosures
22
HHS OCR · State AG · 5 jurisdictions
Incidents
3
filings grouped by incident
Max affected reported
484,157
as filed · HHS OCR CT
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- AETNA INC.
- Normalized
- aetna— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300QKBENKLBXQ8968
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- aetna.com
- Corporate parent
- CVS HEALTH CORPORATION— per GLEIF relationship records
Disclosure history (22)newest first
- CTHHS OCRas victim2026-02-27
Aetna (Business Associate, CT) reported to HHS OCR on 2026-02-27 an Unauthorized Access/Disclosure affecting 10,888 individuals. Breached information was located on Paper/Films. A business associate was present. No further description was provided.
- CTHHS OCRas victim2026-02-27
Aetna reported to HHS on 2026-02-27 a Unauthorized Access/Disclosure affecting 775 individuals. Breached information located on Paper/Films.
- CTHHS OCRas victim2022-12-27
Aetna ACE (CT, Health Plan) reported to HHS on 2022-12-27 a Hacking/IT Incident affecting 4,222 individuals. Several employees were the subjects of an email phishing scheme. PHI exposed included names, medications, diagnoses, and health insurance and other treatment information. Breached information was located in Email. The CE notified HHS, affected individuals, and the media, and implemented additional technical and security safeguards; staff were retrained on email security.
- 🐻California State AGas victim2022-07-27
Aetna, via its vendor OneTouchPoint, Inc. (OTP), disclosed a ransomware incident discovered on April 28, 2022. Unauthorized access to OTP servers began April 27, 2022, resulting in encrypted files. OTP engaged forensic specialists and law enforcement. Customer data, including names and specific data elements, was present on impacted servers; Social Security numbers were not affected. Notification was sent to affected individuals starting June 3, 2022. No evidence of misuse was found.
- CTHHS OCRas victim2022-02-15
Aetna ACE (Health Plan, CT) reported to HHS on 2022-02-15 a Hacking/IT Incident affecting 893 individuals. The breach occurred at a business associate and impacted PHI including names, dates of birth, addresses, claims information, diagnoses, lab results, medications, and other treatment information. Breached information located on Network Server. The CE notified HHS, affected individuals, and media, and implemented additional technical safeguards, credit monitoring, and employee retraining.
- CTHHS OCRas victim2021-09-22
Aetna ACE (Health Plan, CT) reported to HHS on 2021-09-22 a Hacking/IT Incident (email phishing) affecting 1,011 individuals. An employee of the covered entity's business associate was the victim of an email phishing scheme. PHI involved included names, dates of birth, diagnoses/conditions, and other treatment information. Breached information was located in Email. The CE notified HHS, affected individuals, and the media.
- 🦫Oregon State AGas victim2021-07-26
Aetna reported a data breach to the Oregon Attorney General. The breach was reported on 2021-07-26. The breach occurred during 8/6/2020 - 10/2/2020. The breach was discovered on 6/21/2021. 8,664 individuals were affected. Notice was sent on 7/13/2021.
- CTHHS OCRas victim2021-07-14
Aetna ACE reported to HHS on 2021-07-14 a Hacking/IT Incident affecting 8664 individuals. Breached information located on Email. A business associate was the victim of an email phishing attack that compromised electronic protected health information (ePHI) including names, DOB, SSN, and treatment data.
- CTHHS OCRas victim2021-05-26
Aetna ACE reported to HHS on 2021-05-26 a Unauthorized Access/Disclosure affecting 562 individuals. Breached information located on Paper/Films. An employee inadvertently sent PHI (names, DOB, insurance, claims, treatment info) to wrong recipients. The CE implemented additional administrative and technological safeguards.
- CTHHS OCRas victim2020-12-22
Aetna ACE (Health Plan, CT) reported to HHS on 2020-12-22 a Hacking/IT Incident affecting 484,157 individuals. Multiple employees of its business associate experienced a phishing attack compromising ePHI via Email. Exposed data included names, addresses, Social Security numbers, dates of birth, diagnoses, and financial/treatment information. The CE notified HHS, affected individuals, and the media, and revised its BA-related policies and procedures.
- 🐻California State AGas reporting2020-12-11
Aetna (via EyeMed) reported a data breach affecting vision benefit recipients. An unauthorized individual accessed an EyeMed email mailbox on June 24, 2020, and sent phishing emails to the address book. Access was terminated on July 1, 2020. Personal information of individuals receiving vision benefits may have been viewed or copied. EyeMed engaged a cybersecurity firm, reset passwords, and provided two years of free identity monitoring via Kroll.
- 🦫Oregon State AGas victim2020-12-10
Aetna reported a data breach to the Oregon Attorney General. The breach was reported on 2020-12-10. The breach occurred during 6/24/2020 - 7/1/2020. The breach was discovered on 7/1/2020. Notice was sent on 12/10/2020.
- CTHHS OCRas victim2020-07-29
Aetna ACE (Health Plan, CT) reported to HHS OCR on 2020-07-29 a Hacking/IT Incident affecting 1,084 individuals. Employees of Aetna ACE's business associate were victims of an email phishing scheme that compromised ePHI, including names, addresses, telephone numbers, diagnoses, health insurance information, and treatment information. Breached information was located in Email. Aetna notified OCR and affected individuals.
- CTHHS OCRas victim2019-12-13
Aetna affiliated covered entity (ACE) reported to HHS on 2019-12-13 a Hacking/IT Incident affecting 5991 individuals. Breached information located on Email. Business associate National Imaging Associates was the victim of an email phishing scheme.
- CTHHS OCRas victim2017-11-08
Aetna Inc. reported to HHS on 2017-11-08 a Unauthorized Access/Disclosure affecting 1600 individuals. Breached information located on Paper/Films. Aetna settled potential HIPAA violations for $1,000,000 involving impermissible disclosures of PHI via web services and mail.
- CTHHS OCRas victim2017-10-23
Aetna, Inc. (Health Plan, CT) reported to HHS on 2017-10-23 an Unauthorized Access/Disclosure affecting 1,506 individuals. A business associate, Real Time Health Quotes LLC (an insurance producer), stored PHI in an unsecured cloud storage application. Exposed data included names, dates of birth, Social Security numbers, medical histories, bank account, and credit card information. Aetna notified HHS, media, and affected individuals; offered free credit monitoring; terminated the BA relationship; and initiated a review of cloud storage use among similar BAs. Breached information located on Network Server.
- CTHHS OCRas victim2017-08-29
Aetna Inc. reported to HHS on 2017-08-29 a Unauthorized Access/Disclosure affecting 11887 individuals. Breached information located on Paper/Films. Aetna settled potential HIPAA violations for $1,000,000 involving impermissible disclosures of PHI via web services and mail envelopes.
- 🦫Oregon State AGas victim2017-07-10
Aetna, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2017-07-10. The breach occurred during 2/1/2017 - 4/28/2017. The breach was discovered on 4/24/2017. 5,002 individuals were affected. Notice was sent on 6/21/2017.
- 🦬Montana State AGas victim2017-06-21
Aetna reported a data breach to the Montana Attorney General. The breach was reported on 2017-06-21. The breach occurred on 4/27/2017. 11 Montana residents were affected.
- FEDERALHHS OCRas victim2017-06-20
Aetna Inc. (CT, Health Plan) reported to HHS OCR on 2017-06-20 an Unauthorized Access/Disclosure affecting 5,002 individuals. On April 27, 2017, two web services displaying plan documents allowed access without login credentials and were indexed by internet search engines, exposing names, insurance IDs, claim payment amounts, procedure codes, and dates of service. Separately, envelope mailings in July and September 2017 inadvertently disclosed HIV medication and atrial fibrillation study participation to additional members. OCR settled with Aetna for $1,000,000 plus a corrective action plan. Breached information located on Network Server.
- 🦬Montana State AGas victim2016-11-16
Aetna reported a data breach to the Montana Attorney General. The breach was reported on 2016-11-16. The breach occurred on 9/9/2016. 34 Montana residents were affected.
- CTHHS OCRas victim2010-07-27
Aetna (Health Plan, CT) reported to HHS OCR on 2010-07-27 an Unauthorized Access/Disclosure breach affecting 6,372 individuals. Breached information was located on Paper/Films. No business associate was involved. No further detail was provided in the web description.