Premera Blue Cross
ent_019e0b1f85f38a21389031b19569dd71
Disclosures
16
State AG · HHS OCR · HHS OCR enforcement · 9 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
11,000,000
nationwide · HHS OCR WA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Premera Blue Cross
- Normalized
- premera blue cross— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 254900KWJY79FQ8UXW70
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- premera.com
Disclosure history (16)newest first
- Washington State AGas victim2024-04-19
Supplemental notice for Welltok, Inc. on behalf of Premera Blue Cross regarding a MOVEit Transfer server compromise. An unknown actor exploited vulnerabilities to access the server on May 30, 2023, exfiltrating names, addresses, DOBs, and member IDs. Welltok was alerted on July 26, 2023. Notices sent to 2,384 Washington residents on Jan 15, 2024.
- WASHINGTONHHS OCRas victim2023-08-08
Premera Blue Cross reported to HHS on 2023-08-08 a Hacking/IT Incident affecting 33,212 individuals. Breached information located on Network Server. A software application used by a business associate exposed PHI including names, addresses, DOB, phone numbers, and health insurance info. CE and BA implemented additional safeguards.
- Washington State AGas victim2023-07-10
Premera Blue Cross notified the Washington AG of a ransomware attack on its business associate, Kern Agency, involving an exploit of MOVEit software. The incident occurred May 31-June 1, 2023, and was discovered June 3, 2023. 33,237 Medicare Advantage members' PHI (names, DOB, member ID, etc.) was exfiltrated. Kern engaged forensic investigators and the FBI. Notifications were sent July 13, 2023.
- Washington State AGas victim2023-03-05
Premera Blue Cross notified the Washington AG of a breach affecting its business associate Brightline, which was impacted by a vulnerability in Fortra's GoAnywhere MFT service. The incident, occurring Jan 28-30, 2023, exposed personal info (names, DOBs, addresses, emails) for 173,989 members, including 36,211 in WA. Fortra exploited a previously unknown vulnerability and used valid accounts to exfiltrate data.
- Montana State AGas victim2022-06-10
Premera Blue Cross notified Montana residents of a credential stuffing attack on its pharmacy vendor, Express Scripts, affecting mobile app users. The incident, discovered May 17, 2022, potentially exposed names, prescription history, and credentials. Premera reset accounts and offered credit monitoring.
- Illinois State AGas victim2022-01-01
PREMERA BLUE CROSS filed a data-breach notice with the Illinois Attorney General during 2022 (case 2022-355). The register records the breach as discovered on March 22, 2022. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- FEDERALHHS OCR enforcementas victim2020-09-25
Premera Blue Cross agreed to pay $6.85 million to settle potential HIPAA Privacy and Security Rules violations related to a breach affecting over 10.4 million people. The settlement includes a corrective action plan.
- New Hampshire State AGas victim2015-05-04
Premera, Inc., a downstream subcontractor to BCBSMA, suffered a cyber-attack starting May 5, 2014, discovered Jan 9, 2015. Nuance Communications, Inc. reports 717 impacted plan participants, including 1 in NH. Data accessed included PII, SSN, PHI, and financial data. Notices sent April 2015.
- New Hampshire State AGas victim2015-04-02
Weyerhaeuser notified New Hampshire AG of its role in notifying enrollees affected by the Premera Blue Cross breach. Premera detected unauthorized access starting May 2014, discovered on Jan 29, 2015. Data included PII and PHI. Weyerhaeuser is sending letters to enrollees.
- New Hampshire State AGas victim2015-03-27
Premera Blue Cross suffered a cyberattack with initial access on May 5, 2014, discovered on Jan 29, 2015. HCSC notified NH AG on March 27, 2015, that NH residents were impacted. Data accessed included names, SSNs, DOBs, bank info, and PHI. Premera engaged Mandiant and notified the FBI. No evidence of data removal or misuse was found at the time of notification.
- Hawaii State AGas victim2015-03-24
Premera Blue Cross notified Hawaii regulators of a cyberattack where unauthorized access to IT systems occurred on May 5, 2014, and was discovered on January 29, 2015. Attackers may have accessed names, SSNs, DOBs, bank accounts, and clinical data. Premera engaged Mandiant for investigation, notified the FBI, and began notifying affected individuals on March 17, 2015, offering two years of credit monitoring.
- South Carolina State AGas victim2015-03-19
Premera Blue Cross notified members of a sophisticated cyberattack where attackers gained unauthorized access to IT systems starting May 5, 2014. Discovered Jan 29, 2015, the breach may have exposed names, SSNs, DOBs, bank info, and clinical data. Premera engaged Mandiant, notified the FBI, and offered two years of credit monitoring. No evidence of data removal or misuse was found at the time of notification.
- Massachusetts State AGas victim2015-03-18
Premera Blue Cross reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2015-03-18. 173 Massachusetts residents were affected. The report records the breach type as electronic.
- WASHINGTONHHS OCRas victim2015-03-17
Premera Blue Cross (WA/AK) reported to HHS OCR on 2015-03-17 a Hacking/IT Incident affecting 11,000,000 individuals, with breached information located on Network Servers. Attackers used a phishing email in May 2014 to install malware enabling unauthorized access for ~9 months until January 2015 (advanced persistent threat). Exposed PHI included names, addresses, dates of birth, email addresses, SSNs, bank account information, and health plan clinical data for 10.4M+ individuals. PBC settled with OCR for $6.85M — the second-largest HIPAA resolution in OCR history — and agreed to a corrective action plan with two years of monitoring.
- California State AGas victim2015-03-17
Premera Blue Cross filed a data breach notification with the California Attorney General. The filing includes sample notices for adults, deceased individuals, and minors. The specific details of the breach (dates, counts, attack vector) are contained within the attached PDF letters, which are not fully parsed in this extraction. Premera is a healthcare insurer.
- New Hampshire State AGas victim2015-03-17
Premera Blue Cross notified the NH AG of a cyberattack discovered Jan 29, 2015, with initial access occurring May 5, 2014. Attackers may have accessed PHI, SSNs, and financial data. No evidence of data removal or fraud found. Premera engaged Mandiant, notified the FBI, and offered 2 years of credit monitoring. Total affected count unknown.