HUMANA INC.
ent_019e0a6ec26b58f2099d2bd2fbe0fde0
Disclosures
25+
State AG · HHS OCR · SEC 10-K Item 1C · Leak Site · 11 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
22,767
nationwide · State AG ME
Leak-site claims
2
unverified actor claims
Identity resolution
- Canonical name
- HUMANA INC.
- Normalized
- humana— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 529900YLDW34GJAO4J06
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- humana.com
Disclosure history (newest 25)newest first
- 🍁Vermont State AGas victim2026-07-23
Humana Inc. reported a data breach to the Vermont Attorney General. The breach was reported to the AGO on 2026-07-23. The reporting organization type is Insurance. 3 Vermont residents were affected. Categories of data breached: Social Security Numbers, Health Records.
- ⭐Texas State AGas victim2026-06-18
Humana Inc based in Louisville, Kentucky, a insurance services entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-04-30 and reported on 2026-06-18. 2,104 Texas residents were affected. 15,624 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Medical Information;Health Insurance Information;Date of Birth. Consumers were notified via Posted at company website or special website;U.S. Mail.
- ⛰️New Hampshire State AGas victim2026-06-12
Humana Inc. notified the New Hampshire Attorney General of a security incident involving its law firm, Pillsbury Winthrop Shaw Pitman LLP. In April 2025, Pillsbury was targeted by social engineering (phishing). An unauthorized actor downloaded Humana litigation documents containing PHI, PII, and financial data. Discovery occurred in December 2025. One NH resident was affected. Notifications were sent in June 2026, offering 24 months of credit monitoring.
- 🏛️Massachusetts State AGas victim2026-06-01
Pillsbury Winthrop Shaw Pitman LLP notified Humana and affected individuals of a security event where sophisticated social engineering (phishing) targeted law firms, allowing an unauthorized actor to download court-case documents belonging to Humana. The breach exposed personal information, including Social Security Numbers, credit/debit card numbers, and bank account numbers. Humana is providing 24 months of free credit monitoring through Equifax. The incident is contained.
- ⭐Texas State AGas victim2026-04-24
HUMANA INC based in Louisville, Kentucky, a insurance services entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-02-18 and reported on 2026-04-24. 2,104 Texas residents were affected. 15,624 individuals affected in total. Types of information involved: Name of individual;Social Security Number Information;Medical Information;Health Insurance Information.
- 🏎️Indiana State AGas victim2026-03-16
Humana Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2025-08-14 and was reported on 2026-03-16. 3 Indiana residents were affected. 553 individuals affected in total.
- KYHHS OCRas victim2026-02-28
Insurance ACE/Humana Inc. (a Health Plan based in KY) reported to HHS OCR on 2026-02-28 a Hacking/IT Incident affecting 1,000 individuals. Breached information was located on a Network Server. A business associate was present. No further details were provided in the HHS web description.
- FEDERALSEC 10-K Item 1Cas victim2026-02-19
Humana Inc. (Form 10-K, Item 1C) discloses that it has been subject to cybersecurity breaches, including those affecting third-party service providers, but states the impact has not been material to its business or financial results through December 31, 2025. The filing details a comprehensive risk management program, including a 24/7 Cybersecurity Operations Center, annual SOC 2 audits, employee training, and reporting breaches to HHS/OCR. No specific incident details, dates, or affected counts are provided.
- GLOBALLeak Siteas victim2025-11-21
Humana Inc. is a leading US-based health insurance company, founded in 1961. Its coverage extends across the country, providing a range of insurance products and health and wellness services. These include medical, dental, and vision insurance, along with pharmacy services and health information technology solutions. Humana largely focuses on senior citizens, especially those enrolled in Medicare. The company is keen on fostering healthy habits and promoting preventive care efforts.
- 🏎️Indiana State AGas victim2025-04-29
Humana Inc reported a data breach to the Indiana Attorney General. 161 Indiana residents were affected. 15,624 individuals affected in total.
- KYHHS OCRas victim2025-02-06
Insurance ACE/Humana Inc. (KY, Health Plan) reported to HHS on 2025-02-06 an Unauthorized Access/Disclosure affecting 8,553 individuals. A mailing incident exposed PHI including names, addresses, and diagnoses/conditions on Paper/Films. A business associate was present. The CE notified HHS, affected individuals, and the media. Corrective actions included changes in mailing procedures to better protect PHI.
- KYHHS OCRas victim2024-06-05
Insurance ACE/Humana Inc. reported to HHS on 2024-06-05 a Unauthorized Access/Disclosure affecting 15003 individuals. Breached information located on Paper/Films.
- FEDERALSEC 10-K Item 1Cas victim2024-02-15
Humana's FY2023 Form 10-K Item 1C cybersecurity disclosure describes its risk management program, board oversight via Audit and Technology Committees, and CISO/CIO governance structure. The filing acknowledges the company has been subject to past breaches of its own and third-party service providers' IT systems but states the impact has not been material through December 31, 2023. No specific incident, date, count, or data type is disclosed.
- KYHHS OCRas victim2024-02-14
Insurance ACE/Humana Inc. reported to HHS on 2024-02-14 a Unauthorized Access/Disclosure affecting 3480 individuals. Breached information located on Paper/Films. An employee of a business associate mailed PHI (diagnoses, medications, treatment info) to wrong recipients. The CE notified HHS, individuals, and media, and provided substitute website notice. The BA retrained and sanctioned the employee.
- KYHHS OCRas victim2024-02-08
Humana Inc. (KY, Health Plan) reported to HHS OCR on 2024-02-08 an Unauthorized Access/Disclosure affecting 12,339 individuals. An unauthorized external individual accessed PHI stored on a Network Server using credentials or data obtained from an outside source. PHI affected included names, addresses, dates of birth, diagnoses, and other treatment information. Humana notified HHS and affected individuals, and implemented additional administrative and technical safeguards.
- KYHHS OCRas victim2024-02-06
Humana Inc. (KY) reported to HHS on 2024-02-06 an Unauthorized Access/Disclosure affecting 6,440 individuals. An employee inadvertently mailed PHI — including names, addresses, medications, and diagnoses — to the wrong recipients. Breached information was on Paper/Films. No business associate was involved. Humana notified HHS, affected individuals, and the media, and implemented additional administrative, technical, and security safeguards.
- KYHHS OCRas victim2023-12-21
Humana Inc. reported to HHS on 2023-12-21 a Hacking/IT Incident affecting 2844 individuals. Breached information located on Network Server. A vendor of Humana's business associate experienced a cyber-attack compromising PHI (names and claims). Humana notified HHS, individuals, and media, and implemented new technical safeguards.
- 🐻California State AGas reporting2023-12-13
Prospect Medical Holdings, Inc. notified individuals of a data security incident where unauthorized parties accessed its IT environment between July 31 and August 3, 2023. The activity was first identified on August 1, 2023. Systems were taken offline immediately. Files containing protected health information (PHI) and personal information were accessed or acquired. A third-party forensics firm assisted in the investigation.
- 🦞Maine State AGas victim2023-10-24
Humana Inc. experienced an external system breach (hacking) on August 9, 2023, which was discovered on October 3, 2023. The incident affected 16 residents of Maine, who were notified on November 3, 2023.
- FEDERALHHS OCRas victim2023-06-15
Humana Inc. reported to HHS on June 15, 2023, a breach affecting 9,372 individuals. An employee inadvertently placed patient diagnoses on the outside of mailing envelopes, which involved paper records. The exposed information included names, addresses, and diagnoses. In response, Humana revised its policies and procedures, retrained its workforce, and sanctioned the responsible employee.
- GLOBALLeak Siteas victim2023-05-09
Humana is a leading Nordic care company providing services within individual and family care, personal assistance, elderly care and special service housing in accordance with LSS.
- 🦞Maine State AGas victim2022-09-21
Humana, a healthcare entity based in Louisville, KY, reported an external system breach (hacking) occurring on May 7, 2022, discovered on July 26, 2022. The incident affected 22,767 individuals, including 23 Maine residents. Acquired information included names and Social Security Numbers. Humana notified affected individuals in writing on June 8, 2022, and offered 2 years of identity theft protection services through Experian.
- 🌲Washington State AGas victim2022-09-08
Humana, Inc., a health sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2022-08-05 and filed notice on 2022-09-08. 639 Washington residents were affected. 34 days elapsed between awareness and notification. 90 days to identify the breach.
- 🐻California State AGas reporting2021-12-06
Team Alvarez Insurance Services suffered a ransomware attack on August 25, 2021, encrypting servers and potentially exposing customer PII including names, SSNs, Medicare IDs, and financial account details. The company engaged legal counsel and law enforcement, rebuilt servers, and offered 12 months of credit monitoring.
- KYHHS OCRas victim2021-11-09
Humana Inc. (KY, Health Plan) reported to HHS on 2021-11-09 a Hacking/IT Incident affecting 1,823 individuals. A business associate experienced a ransomware attack that encrypted ePHI stored on a network server. Exposed data included names, addresses, dates of birth, Social Security numbers, diagnoses and medical conditions, medications prescribed, and other treatment information. The BA notified affected individuals and media, and provided complimentary credit monitoring. OCR provided technical assistance on the HIPAA Breach Notification Rule.