HUMANA INC.
ent_019e0a6ec26b58f2099d2bd2fbe0fde0
Disclosures
25+
State AG · HHS OCR · Leak Site · 11 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
189,492
nationwide · State AG NH
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- HUMANA INC.
- Normalized
- humana— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 529900YLDW34GJAO4J06
- SEC EDGAR CIK
- 0000049071
- Domain
- humana.com
Disclosure history (newest 25)newest first
- Idaho State AGas reporting2026-08-12
DentaQuest, a dental and vision benefits provider for Humana Medicaid and D-SNP plans, experienced a data breach affecting 26 Idaho residents. A threat actor used social engineering to compromise an employee account, gaining unauthorized access to DentaQuest's IT environment from May 17-20, 2026. The accessed data included names, addresses, member IDs, Medicaid/Medicare numbers, dental/vision health information, and in some cases, Social Security Numbers. DentaQuest contained the incident, engaged CrowdStrike for investigation, and is offering 24 months of identity monitoring via Kroll. Humana notified the Idaho Attorney General as part of its Business Associate agreement.
- Idaho State AGas reporting2026-07-30
DentaQuest, LLC, a dental and vision benefits provider for Humana Medicaid/D-SNP plans, experienced a security incident impacting 26 Idaho residents. A threat actor gained unauthorized access to DentaQuest's IT environment on May 17, 2026, using compromised credentials obtained via a social engineering attack targeting a single employee. The actor accessed personal and health information (including SSNs) before being contained on May 19, 2026. Humana notified the Idaho AG on July 30, 2026. Affected individuals received notification letters and offers for credit monitoring via Kroll.
- New Hampshire State AGas reporting2026-07-29
DentaQuest, LLC, a dental and vision benefits provider for Humana Medicaid and D-SNP plans, reported a cybersecurity incident to the New Hampshire Attorney General on July 29, 2026. This is a supplemental notice to a prior filing from July 17, 2026. The breach involved unauthorized access via a social engineering attack targeting a single employee's SSO credentials. The incident occurred between May 17 and May 20, 2026. Data exposed includes names, addresses, SSNs, Medicaid/Medicare numbers, and dental/vision health information. 189,492 individuals were affected nationwide, including 5 in New Hampshire. The threat actor posted data on the internet. DentaQuest engaged CrowdStrike, revoked access, and offered 24 months of Kroll identity monitoring.
- Vermont State AGas victim2026-07-23
Humana Inc. reported a data breach to the Vermont Attorney General. The breach was reported to the AGO on 2026-07-23. The reporting organization type is Insurance. 3 Vermont residents were affected. Categories of data breached: Social Security Numbers, Health Records.
- Texas State AGas victim2026-06-18
Humana Inc based in Louisville, Kentucky, a insurance services entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-04-30 and reported on 2026-06-18. 2,104 Texas residents were affected. 15,624 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Medical Information;Health Insurance Information;Date of Birth. Consumers were notified via Posted at company website or special website;U.S. Mail.
- New Hampshire State AGas victim2026-06-12
Humana Inc. notified the New Hampshire Attorney General of a security incident involving its law firm, Pillsbury Winthrop Shaw Pitman LLP. In April 2025, Pillsbury was targeted by social engineering (phishing). An unauthorized actor downloaded Humana litigation documents containing PHI, PII, and financial data. Discovery occurred in December 2025. One NH resident was affected. Notifications were sent in June 2026, offering 24 months of credit monitoring.
- Massachusetts State AGas victim2026-06-12
Pillsbury Winthrop Shaw Pitman LLP notified Humana and affected individuals of a security event where sophisticated social engineering (phishing) targeted law firms, allowing an unauthorized actor to download court-case documents belonging to Humana. The breach exposed personal information, including Social Security Numbers, credit/debit card numbers, and bank account numbers. Humana is providing 24 months of free credit monitoring through Equifax. The incident is contained.
- Nebraska State AGas victim2026-06-01
Pillsbury Winthrop Shaw Pitman LLP notified Humana patients in Nebraska of a security incident where sophisticated social engineering (phishing) targeted law firms, allowing an unauthorized actor to download documents from Humana's court case files. The breach exposed personal information including Social Security Numbers, credit/debit card numbers, and bank account numbers. Humana offered 24 months of free credit monitoring through Equifax. The incident date is June 1, 2026.
- KENTUCKYHHS OCRas victim2026-05-15
Insurance ACE/Humana Inc. reported to HHS on 2026-05-15 a Unauthorized Access/Disclosure affecting 1761 individuals. Breached information located on Network Server.
- Illinois State AGas victim2026-05-01
HUMANA filed a data-breach notice with the Illinois Attorney General in May 2026 (case 26-05-1176). The register records the breach as discovered on February 27, 2026. Additional entities named: PILLSBURY WINTHROP SHAW PITTMAN, LLP. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2026-05-01
HUMANA filed a data-breach notice with the Illinois Attorney General in May 2026 (case 26-05-1177). The register records the breach as discovered on September 29, 2025. Personal information types reported: drivers license, medical information, ssn. Additional entities named: ORACLE SOFTWARE. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Idaho State AGas victim2026-04-30
Humana Inc reported a security incident on April 22, 2026, notifying the Idaho AG. On Feb 27, 2026, outside counsel for the plaintiff in AAAPC v. Humana (Pillsbury Winthrop Shaw Pittman LLP) suffered a breach via social engineering/phishing. An unauthorized actor accessed a file server containing Humana discovery documents and exfiltrated materials. The event was under investigation as of filing.
- Texas State AGas victim2026-04-24
HUMANA INC based in Louisville, Kentucky, a insurance services entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-02-18 and reported on 2026-04-24. 2,104 Texas residents were affected. 15,624 individuals affected in total. Types of information involved: Name of individual;Social Security Number Information;Medical Information;Health Insurance Information.
- Idaho State AGas victim2026-03-27
Humana Inc. notified the Idaho Attorney General of a security incident impacting 2 Idaho residents. Unauthorized access occurred in August 2025 via a previously unknown Oracle vulnerability. Data exposed included names, SSNs, patient account numbers, and PHI. Notification letters were sent on March 16, 2026. Humana engaged Oracle, notified law enforcement, and provided 24 months of credit monitoring.
- Massachusetts State AGas victim2026-03-18
Humana Inc. disclosed unauthorized access to internal systems in August 2025, discovered on September 29, 2025. The incident was caused by a vendor's software vulnerability involving Oracle. Affected data included names, Humana ID numbers, Social Security numbers, and medical billing/claims information. Humana worked with Oracle to address the vulnerability, notified law enforcement, and is providing 24 months of credit monitoring and identity restoration services through Equifax.
- Indiana State AGas victim2026-03-16
Humana Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2025-08-14 and was reported on 2026-03-16. 3 Indiana residents were affected. 553 individuals affected in total.
- KENTUCKYHHS OCRas victim2026-02-28
Insurance ACE/Humana Inc. (a Health Plan based in KY) reported to HHS OCR on 2026-02-28 a Hacking/IT Incident affecting 1,000 individuals. Breached information was located on a Network Server. A business associate was present. No further details were provided in the HHS web description.
- GLOBALLeak Siteas victim2025-11-21
Humana Inc. is a leading US-based health insurance company, founded in 1961. Its coverage extends across the country, providing a range of insurance products and health and wellness services. These include medical, dental, and vision insurance, along with pharmacy services and health information technology solutions. Humana largely focuses on senior citizens, especially those enrolled in Medicare. The company is keen on fostering healthy habits and promoting preventive care efforts.
- Washington State AGas victim2025-05-12
MedicareCompareUSA filed a Washington AG notice on behalf of Humana regarding a phishing incident affecting 922 WA residents. Unauthorized access to email accounts occurred Nov 5-21, 2024. Data exposed included names, DOBs, Medicare/Medicaid numbers, and SSNs. Notices sent May 12, 2025. Credit monitoring offered.
- Indiana State AGas victim2025-04-29
Humana Inc reported a data breach to the Indiana Attorney General. 161 Indiana residents were affected. 15,624 individuals affected in total.
- KENTUCKYHHS OCRas victim2025-02-06
Insurance ACE/Humana Inc. (KY, Health Plan) reported to HHS on 2025-02-06 an Unauthorized Access/Disclosure affecting 8,553 individuals. A mailing incident exposed PHI including names, addresses, and diagnoses/conditions on Paper/Films. A business associate was present. The CE notified HHS, affected individuals, and the media. Corrective actions included changes in mailing procedures to better protect PHI.
- Illinois State AGas victim2024-12-01
HUMANA, INC. filed a data-breach notice with the Illinois Attorney General in December 2024 (case 24-12-013). The register records the breach as discovered on November 12, 2024. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2024-07-01
HUMANA, INC. filed a data-breach notice with the Illinois Attorney General in July 2024 (case 24-07-028). The register records the breach as discovered on June 14, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- KENTUCKYHHS OCRas victim2024-06-05
Insurance ACE/Humana Inc. reported to HHS on 2024-06-05 a Unauthorized Access/Disclosure affecting 15003 individuals. Breached information located on Paper/Films.
- Illinois State AGas victim2024-03-01
HUMANA, INC. PRIVACY OFFICE filed a data-breach notice with the Illinois Attorney General in March 2024 (case 24-03-061). The register records the breach as discovered on September 8, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
Subsidiary disclosures (2)filed by group companies
◈ These filings were made by or about subsidiaries of HUMANA INC. — not by HUMANA INC. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- Illinois State AGvia HUMANA INSURANCE COMPANY2026-03-01
HUMANA INSURANCE ACE filed a data-breach notice with the Illinois Attorney General in March 2026 (case 26-03-1042). The register records the breach as discovered on February 11, 2025. Personal information types reported: drivers license, financial account number. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Indiana State AGvia HUMANA INSURANCE COMPANY2023-02-13
Humana Insurance Company reported a data breach to the Indiana Attorney General. The breach occurred on 2023-01-09 and was reported on 2023-02-13. 1 Indiana residents were affected.