AETNA INC.
ent_019e07ca49ec446a0ba664c4140f7cee
Disclosures
25+
HHS OCR · State AG · 7 jurisdictions
Multi-filing incidents
6
incidents joining 2+ filings here
Max affected reported
484,157
nationwide · HHS OCR CT
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- AETNA INC.
- Normalized
- aetna— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300QKBENKLBXQ8968
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- aetna.com
- Corporate parent
- CVS HEALTH CORPORATION— per GLEIF relationship records
Disclosure history (newest 25)newest first
- CONNECTICUTHHS OCRas victim2026-02-27
Aetna (Business Associate, CT) reported to HHS OCR on 2026-02-27 an Unauthorized Access/Disclosure affecting 10,888 individuals. Breached information was located on Paper/Films. A business associate was present. No further description was provided.
- CONNECTICUTHHS OCRas victim2026-02-27
Aetna reported to HHS on 2026-02-27 a Unauthorized Access/Disclosure affecting 775 individuals. Breached information located on Paper/Films.
- CONNECTICUTHHS OCRas victim2024-12-20
Aetna ACE (Health Plan, CT) reported to HHS on 2024-12-20 an Unauthorized Access/Disclosure affecting 1,317 individuals. A business associate employee mailed PHI — including names, addresses, and medications — to wrong recipients. Breached information was located on Other Portable Electronic Device. The CE notified HHS and affected individuals; the BA implemented additional administrative and technical safeguards in response.
- CONNECTICUTHHS OCRas victim2024-05-03
Aetna ACE (CT, Health Plan) reported to HHS on 2024-05-03 a Hacking/IT Incident affecting 9,191 individuals. A vendor of its business associate experienced a cyber-attack that compromised PHI including names, addresses/zip codes, birthdates, and other identifiers. Breached information was located on a Network Server. HHS and affected individuals were notified.
- Washington State AGas victim2024-02-28
Welltok, Inc. reported a supplemental data event on behalf of Aetna ACE involving the MOVEit Transfer server. An unknown actor exploited software vulnerabilities to access the server on May 30, 2023, and exfiltrated data including names, diagnoses, and health insurance info. Welltok was alerted on July 26, 2023. Notices were sent to 2,653 Washington residents starting Feb 23, 2024.
- Massachusetts State AGas victim2023-12-14
Aetna reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-12-14. 12 Massachusetts residents were affected. The report records the breach type as electronic.
- CONNECTICUTHHS OCRas victim2022-12-27
Aetna ACE (CT, Health Plan) reported to HHS on 2022-12-27 a Hacking/IT Incident affecting 4,222 individuals. Several employees were the subjects of an email phishing scheme. PHI exposed included names, medications, diagnoses, and health insurance and other treatment information. Breached information was located in Email. The CE notified HHS, affected individuals, and the media, and implemented additional technical and security safeguards; staff were retrained on email security.
- Indiana State AGas victim2022-12-23
Aetna ACE reported a data breach to the Indiana Attorney General. The breach occurred on 2022-06-02 and was reported on 2022-12-23. 1 Indiana residents were affected. 110 individuals affected in total.
- California State AGas victim2022-07-27
OneTouchPoint, Inc., a vendor for Aetna and other health insurers, discovered unauthorized access to its servers on April 28, 2022, beginning April 27, 2022. The incident involved encrypted files and potential access to customer health assessment data, including names and other data elements. Social Security numbers were not impacted. Aetna notified affected individuals in June 2022.
- CONNECTICUTHHS OCRas victim2022-07-27
Aetna ACE (Health Plan, CT) reported to HHS on 2022-07-27 a Hacking/IT Incident affecting 325,278 individuals. A vendor of Aetna's business associate experienced a ransomware attack that compromised PHI stored on network servers. Exposed data included names, dates of birth, addresses, health insurance information, lab results, medication information, and financial and claims information. The CE notified HHS, affected individuals, and the media.
- CONNECTICUTHHS OCRas victim2022-02-15
Aetna ACE (Health Plan, CT) reported to HHS on 2022-02-15 a Hacking/IT Incident affecting 893 individuals. The breach occurred at a business associate and impacted PHI including names, dates of birth, addresses, claims information, diagnoses, lab results, medications, and other treatment information. Breached information located on Network Server. The CE notified HHS, affected individuals, and media, and implemented additional technical safeguards, credit monitoring, and employee retraining.
- CONNECTICUTHHS OCRas victim2021-09-22
Aetna ACE (Health Plan, CT) reported to HHS on 2021-09-22 a Hacking/IT Incident (email phishing) affecting 1,011 individuals. An employee of the covered entity's business associate was the victim of an email phishing scheme. PHI involved included names, dates of birth, diagnoses/conditions, and other treatment information. Breached information was located in Email. The CE notified HHS, affected individuals, and the media.
- Oregon State AGas victim2021-07-26
Aetna reported a data breach to the Oregon Attorney General. The breach was reported on 2021-07-26. The breach occurred during 8/6/2020 - 10/2/2020. The breach was discovered on 6/21/2021. 8,664 individuals were affected. Notice was sent on 7/13/2021.
- CONNECTICUTHHS OCRas victim2021-07-14
Aetna ACE reported to HHS on 2021-07-14 a Hacking/IT Incident affecting 8664 individuals. Breached information located on Email. A business associate was the victim of an email phishing attack that compromised electronic protected health information (ePHI) including names, DOB, SSN, and treatment data.
- Indiana State AGas victim2021-07-13
Aetna reported a data breach to the Indiana Attorney General. The breach occurred on 2020-08-06 and was reported on 2021-07-13. 5 Indiana residents were affected. 8,664 individuals affected in total.
- CONNECTICUTHHS OCRas victim2021-05-26
Aetna ACE reported to HHS on 2021-05-26 a Unauthorized Access/Disclosure affecting 562 individuals. Breached information located on Paper/Films. An employee inadvertently sent PHI (names, DOB, insurance, claims, treatment info) to wrong recipients. The CE implemented additional administrative and technological safeguards.
- CONNECTICUTHHS OCRas victim2020-12-22
Aetna ACE (Health Plan, CT) reported to HHS on 2020-12-22 a Hacking/IT Incident affecting 484,157 individuals. Multiple employees of its business associate experienced a phishing attack compromising ePHI via Email. Exposed data included names, addresses, Social Security numbers, dates of birth, diagnoses, and financial/treatment information. The CE notified HHS, affected individuals, and the media, and revised its BA-related policies and procedures.
- California State AGas reporting2020-12-11
EyeMed discovered on July 1, 2020, that an unauthorized individual accessed an email mailbox starting June 24, 2020, and sent phishing emails. The mailbox contained personal information of vision benefits recipients. EyeMed secured the mailbox, engaged a cybersecurity firm, changed passwords, and offered two years of identity monitoring via Kroll.
- Indiana State AGas victim2020-12-11
Aetna reported a data breach to the Indiana Attorney General. The breach occurred on 2020-06-24 and was reported on 2020-12-11. 5,661 Indiana residents were affected. 484,157 individuals affected in total.
- Oregon State AGas victim2020-12-10
Aetna reported a data breach to the Oregon Attorney General. The breach was reported on 2020-12-10. The breach occurred during 6/24/2020 - 7/1/2020. The breach was discovered on 7/1/2020. Notice was sent on 12/10/2020.
- Massachusetts State AGas victim2020-12-10
Aetna reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-12-10. 5,057 Massachusetts residents were affected. The report records the breach type as electronic.
- CONNECTICUTHHS OCRas victim2020-07-29
Aetna ACE (Health Plan, CT) reported to HHS OCR on 2020-07-29 a Hacking/IT Incident affecting 1,084 individuals. Employees of Aetna ACE's business associate were victims of an email phishing scheme that compromised ePHI, including names, addresses, telephone numbers, diagnoses, health insurance information, and treatment information. Breached information was located in Email. Aetna notified OCR and affected individuals.
- Illinois State AGas victim2020-01-01
AETNA filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-273). The register records the breach as discovered on July 29, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2020-01-01
AETNA filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-297). The register records the breach as discovered on August 13, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Massachusetts State AGas victim2019-01-30
Aetna Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-01-30. 10 Massachusetts residents were affected. The report records the breach type as electronic.