Premera Blue Cross
ent_019e0b1f85f38a21389031b19569dd71
Disclosures
7
HHS OCR · State AG · 4 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
11,000,000
as filed · HHS OCR FEDERAL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Premera Blue Cross
- Normalized
- premera blue cross— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 254900KWJY79FQ8UXW70
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- premera.com
Disclosure history (7)newest first
- WASHINGTONHHS OCRas victim2023-08-08
Premera Blue Cross reported to HHS on 2023-08-08 a Hacking/IT Incident affecting 33,212 individuals. Breached information located on Network Server. A software application used by a business associate exposed PHI including names, addresses, DOB, phone numbers, and health insurance info. CE and BA implemented additional safeguards.
- 🌲Washington State AGas victim2023-07-10
Premera Blue Cross, a health sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2023-06-15 and filed notice on 2023-07-10. 33,237 Washington residents were affected. 25 days elapsed between awareness and notification. 15 days to identify the breach. 0 days to contain the breach.
- 🌲Washington State AGas victim2023-03-05
Premera Blue Cross, a health sector entity reported a other incident to the Washington Attorney General. The organization became aware of the incident on 2023-02-10 and filed notice on 2023-03-05. 36,211 Washington residents were affected. 23 days elapsed between awareness and notification. 13 days to identify the breach. 0 days to contain the breach.
- 🌲Washington State AGas victim2022-07-18
Premera Blue Cross, a health sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2022-04-29 and filed notice on 2022-07-18. 1,303 Washington residents were affected. 80 days elapsed between awareness and notification. 2 days to identify the breach. 13 days to contain the breach.
- 🦬Montana State AGas victim2022-06-10
Premera Blue Cross reported a data breach to the Montana Attorney General. The breach was reported on 2022-06-10. The breach occurred on 4/30/2022. 1 Montana residents were affected.
- 🌺Hawaii State AGas victim2015-03-24
Premera Blue Cross reported a data breach to the Hawaii Office of Consumer Protection. The office was notified on 2015/03.24. Breach type: Hackers/Unauthorized Access. 19,174 Hawaii residents were affected. Recovered from the Internet Archive after the notice was removed from the OCP table.
- FEDERALHHS OCRas victim2015-03-17
Premera Blue Cross (WA/AK) reported to HHS OCR on 2015-03-17 a Hacking/IT Incident affecting 11,000,000 individuals, with breached information located on Network Servers. Attackers used a phishing email in May 2014 to install malware enabling unauthorized access for ~9 months until January 2015 (advanced persistent threat). Exposed PHI included names, addresses, dates of birth, email addresses, SSNs, bank account information, and health plan clinical data for 10.4M+ individuals. PBC settled with OCR for $6.85M — the second-largest HIPAA resolution in OCR history — and agreed to a corrective action plan with two years of monitoring.