Highmark Inc
ent_019e0a5a3163468337aee68b3f6bf47e
Disclosures
19
HHS OCR · State AG · 10 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
1,073,316
nationwide · State AG DE
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Highmark Inc
- Normalized
- highmark— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300B6868ZXXEB2Y57
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- highmark.com
Disclosure history (19)newest first
- PENNSYLVANIAHHS OCRas victim2024-03-29
Highmark reported to HHS on 2024-03-29 an Unauthorized Access/Disclosure affecting 6,205 individuals. Breached information located on Paper/Films. An employee mailed PHI to outdated addresses.
- New Hampshire State AGas victim2023-06-26
Highmark Health reported a phishing incident where an employee's email account was compromised between Dec 13-15, 2022. The attacker accessed emails containing PHI and PII (name, SSN) of 696 NH residents. Highmark shut down the mailbox, reset passwords, and engaged forensic consultants. Notices were sent to affected individuals and regulators on Feb 13, 2023.
- Massachusetts State AGas victim2023-04-04
Highmark Health reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-04-04. 1,015 Massachusetts residents were affected. The report records the breach type as electronic.
- Delaware State AGas victim2023-02-15
Highmark Health disclosed a cybersecurity incident discovered on December 15, 2022, involving a phishing email sent to an employee. The employee's email account was compromised between December 13 and 15, 2022. The threat actor accessed emails containing Protected Health Information (PHI) of Highmark members. Affected data includes names, SSNs, member IDs, claims/treatment info, financial account numbers, passwords, addresses, DOBs, and phone numbers. Highmark shut down the mailbox, reset passwords, implemented network blocking, and provided 24 months of Experian IdentityWorks.
- PENNSYLVANIAHHS OCRas victim2023-02-10
Highmark Inc reported to HHS on 2023-02-10 a Hacking/IT Incident affecting 36600 individuals. Breached information located on Email. An employee was subject to an email phishing scheme compromising PHI including names, addresses, SSNs, diagnoses, and financial data.
- PENNSYLVANIAHHS OCRas victim2023-02-10
Highmark, Inc. reported to HHS on 2023-02-10 a Hacking/IT Incident affecting 239,039 individuals. Breached information located on Email. An employee was subject to an email phishing scheme that effected PHI including names, DOB, driver’s license numbers, addresses, SSNs, claims, financial information, diagnoses, and medications. Highmark implemented additional safeguards and provided cybersecurity training to staff.
- Indiana State AGas victim2023-02-10
Highmark Health reported a data breach to the Indiana Attorney General. The breach occurred on 2022-12-13 and was reported on 2023-02-10. 28,888 Indiana residents were affected. 293,039 individuals affected in total.
- Delaware State AGas victim2023-02-10
Highmark, Inc. disclosed a cybersecurity incident occurring between December 13-15, 2022, where an employee clicked a malicious phishing link, compromising their email account. The threat actor accessed emails containing Protected Health Information (PHI) and PII of Highmark members, including names, SSNs, member IDs, claims data, and financial account numbers. Highmark shut down the mailbox, reset passwords, and implemented network blocking. Affected individuals were offered 24 months of Experian IdentityWorks.
- South Carolina State AGas victim2023-02-07
Highmark Health notified individuals of a phishing incident where an employee's email was compromised between Dec 13-15, 2022. The attacker accessed emails containing PHI, including names, enrollment info, claims data, and financial info. Highmark shut down the mailbox, reset passwords, and offered 24 months of Experian IdentityWorks.
- Washington State AGas victim2023-02-06
Highmark Health reported a phishing incident where an employee's email account was compromised between Dec 13-15, 2022. Discovered Dec 15, 2022. Exposed PHI, names, SSNs, and member data for 1,980 Washington residents. Notices sent Feb 13, 2023, offering 24 months of credit monitoring.
- California State AGas victim2023-02-03
Highmark disclosed a cyber security incident where an employee clicked a malicious email link, leading to email account compromise between Dec 13-15, 2022. Protected health information (PHI), including names, SSNs (for some), and treatment info, was potentially accessed. Highmark shut down the mailbox, reset passwords, and offered 24 months of Experian IdentityWorks.
- Maine State AGas victim2023-02-03
Healthcare organization Highmark reported an external system breach that occurred from December 13 to December 15, 2022. The breach was discovered on December 15, 2022, and affected 2,774 Maine residents, compromising their Social Security Numbers. Highmark offered affected individuals 24 months of complimentary credit monitoring and identity theft restoration services.
- Delaware State AGas victim2022-07-27
Highmark Inc. reported a data breach to the Delaware Attorney General. The breach occurred on 2022-04-27. It was discovered on 2022-06-03. Notice was filed on 2022-07-27. 486 Delaware residents were affected. 1,073,316 individuals affected in total. Information involved: health basic.
- PENNSYLVANIAHHS OCRas victim2022-06-30
Highmark, Inc. reported to HHS on 2022-06-30 a Hacking/IT Incident affecting 511 individuals. Breached information located on Network Server. The incident involved a business associate whose cybersecurity incident exposed PHI (names and medication information). Highmark and its BA notified affected individuals and HHS; Highmark implemented new administrative and technical safeguards.
- PENNSYLVANIAHHS OCRas victim2022-03-11
Highmark Inc reported to HHS on 2022-03-11 a Hacking/IT Incident affecting 67147 individuals. Breached information located on Network Server. A subcontractor of its business associate experienced the incident involving PHI including names, DOB, medication, and insurance info.
- Indiana State AGas victim2021-06-30
Highmark Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2020-12-23 and was reported on 2021-06-30. 4 Indiana residents were affected. 5,921 individuals affected in total.
- Montana State AGas victim2021-06-24
MultiPlan Inc., a vendor for Highmark Inc., notified Highmark members in Montana that an outside bad actor gained unauthorized access to an employee's email account between Dec 23, 2020 and Jan 27, 2021. The actor attempted to divert wire payments (BEC) and accessed personal information within billing communications. MultiPlan terminated access, reset credentials, engaged forensic experts, and reported to law enforcement. Affected individuals were offered two years of credit monitoring.
- California State AGas victim2021-06-24
Highmark Inc. notified California residents of a data breach involving its vendor, MultiPlan Inc. On January 27, 2021, MultiPlan identified unauthorized access to an employee's email account by an external actor. The incident occurred between December 23, 2020, and January 27, 2021. The actor's goal was to divert wire payments (Business Email Compromise). Personal information, potentially including account details, may have been accessed. MultiPlan terminated access, changed credentials, engaged forensics, and notified law enforcement. Affected individuals were offered two years of credit monitoring. MultiPlan implemented remediation measures including reinforced email authentication and phishing training.
- PENNSYLVANIAHHS OCRas victim2014-07-08
Highmark Inc. (Business Associate) reported to HHS on 2014-07-08 a misdelivery (Theft) affecting 2,589 individuals. Health profile and care summaries with cover letters were incorrectly mailed to senior members of Highmark Health and their physicians. PHI exposed included names, addresses, phone numbers, dates of birth, unique medical identifiers, gender, medications, and health information. Root cause was a process failure by an employee, who was subsequently terminated.