Highmark Inc
ent_019e0a5a3163468337aee68b3f6bf47e
Disclosures
10
State AG · HHS OCR · 7 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
2,774
as filed · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Highmark Inc
- Normalized
- highmark— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300B6868ZXXEB2Y57
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- highmark.com
Disclosure history (10)newest first
- ⛰️New Hampshire State AGas victim2023-06-26
Highmark Health reported a phishing incident where an employee's email account was compromised between Dec 13-15, 2022. The attacker accessed emails containing PHI and PII (name, SSN) of 696 NH residents. Highmark shut down the mailbox, reset passwords, and engaged forensic consultants. Notices were sent to affected individuals and regulators on Feb 13, 2023.
- 💎Delaware State AGas victim2023-02-15
Highmark Health disclosed a cybersecurity incident discovered on December 15, 2022, involving a phishing email sent to an employee. The employee's email account was compromised between December 13 and 15, 2022. The threat actor accessed emails containing Protected Health Information (PHI) of Highmark members. Affected data includes names, SSNs, member IDs, claims/treatment info, financial account numbers, passwords, addresses, DOBs, and phone numbers. Highmark shut down the mailbox, reset passwords, implemented network blocking, and provided 24 months of Experian IdentityWorks.
- 💎Delaware State AGas victim2023-02-10
Highmark, Inc. disclosed a cybersecurity incident occurring between December 13-15, 2022, where an employee clicked a malicious phishing link, compromising their email account. The threat actor accessed emails containing Protected Health Information (PHI) and PII of Highmark members, including names, SSNs, member IDs, claims data, and financial account numbers. Highmark shut down the mailbox, reset passwords, and implemented network blocking. Affected individuals were offered 24 months of Experian IdentityWorks.
- 🌲Washington State AGas victim2023-02-06
Highmark, a health sector entity reported a phishing incident to the Washington Attorney General. The organization became aware of the incident on 2022-12-15 and filed notice on 2023-02-06. 1,980 Washington residents were affected. 53 days elapsed between awareness and notification. 2 days to identify the breach. 0 days to contain the breach.
- 🐻California State AGas victim2023-02-03
Highmark disclosed a cyber security incident where an employee clicked a malicious email link, leading to email account compromise between Dec 13-15, 2022. Protected health information (PHI), including names, SSNs (for some), and treatment info, was potentially accessed. Highmark shut down the mailbox, reset passwords, and offered 24 months of Experian IdentityWorks.
- 🦞Maine State AGas victim2023-02-03
Healthcare organization Highmark reported an external system breach that occurred from December 13 to December 15, 2022. The breach was discovered on December 15, 2022, and affected 2,774 Maine residents, compromising their Social Security Numbers. Highmark offered affected individuals 24 months of complimentary credit monitoring and identity theft restoration services.
- PAHHS OCRas victim2022-06-30
Highmark, Inc. reported to HHS on 2022-06-30 a Hacking/IT Incident affecting 511 individuals. Breached information located on Network Server. The incident involved a business associate whose cybersecurity incident exposed PHI (names and medication information). Highmark and its BA notified affected individuals and HHS; Highmark implemented new administrative and technical safeguards.
- 🦬Montana State AGas victim2021-06-24
Highmark Inc. reported a data breach to the Montana Attorney General. The breach was reported on 2021-06-24. The breach occurred from 12/23/2020 to 6/27/2021. 63 Montana residents were affected.
- 🐻California State AGas victim2021-06-24
Highmark Inc. reported a data breach involving unauthorized access to a MultiPlan employee's email account. The incident, occurring between Dec 23, 2020, and Jan 27, 2021, exposed customer PII including names, SSNs, and financial account numbers. Highmark engaged forensic experts, notified law enforcement, and provided two years of credit monitoring to affected individuals.
- PAHHS OCRas victim2014-07-08
Highmark Inc. (Business Associate) reported to HHS on 2014-07-08 a misdelivery (Theft) affecting 2,589 individuals. Health profile and care summaries with cover letters were incorrectly mailed to senior members of Highmark Health and their physicians. PHI exposed included names, addresses, phone numbers, dates of birth, unique medical identifiers, gender, medications, and health information. Root cause was a process failure by an employee, who was subsequently terminated.