Cigna International Corporation
ent_019e0c8f18d07f1b7614ad477668311e
Disclosures
8
HHS OCR · State AG · 5 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
3,720
nationwide · HHS OCR CT
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Cigna International Corporation
- Normalized
- cigna international— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 254900IT03032PBFN708
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- cigna.com
Disclosure history (8)newest first
- CONNECTICUTHHS OCRas victim2019-05-16
The covered entity (CE), Cigna, reported that its business associate (BA), Availity had fraudulent provider accounts on its provider portal. This breach affected 3,720 individuals and the protected health information (PHI) involved included names, dates of birth, addresses, and health insurance information. Cigna notified HHS, affected individuals, and the media. Cigna also provided two years of complimentary identity protection services.
- CONNECTICUTHHS OCRas victim2018-10-10
Cigna reported to HHS on 2018-10-10 a Hacking/IT Incident affecting 3500 individuals. Breached information located on Network Server. The incident involved credential stuffing attacks exposing PHI including demographic, health claims, and clinical data.
- Montana State AGas victim2018-10-10
Cigna Corporation disclosed a credential stuffing attack targeting the myCigna customer portal. Suspicious activity was detected on September 5, 2018, with unauthorized access continuing until September 24, 2018. Attackers used stolen credentials from other breaches to access accounts, potentially viewing names, contact info, and medical history. Cigna disabled accounts, engaged forensic investigators, and implemented MFA and IP blocking.
- Oregon State AGas victim2018-10-10
Cigna reported a data breach to the Oregon Attorney General. The breach was reported on 2018-10-10. The breach occurred during 9/5/2018 - 9/5/2018. The breach was discovered on 9/5/2018. Notice was sent on 10/10/2018.
- Massachusetts State AGas victim2018-04-09
Cigna reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-04-09. 7 Massachusetts residents were affected. The report records the breach type as paper.
- Massachusetts State AGas victim2016-07-14
Cigna reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2016-07-14. 1 Massachusetts residents were affected. The report records the breach type as paper.
- CONNECTICUTHHS OCRas victim2014-04-09
Cigna reported to HHS on 2014-04-09 a Loss affecting 527 individuals. Breached information located on Paper/Films.
- California State AGas reporting2012-04-19
Cigna Dental disclosed that an employee emailed an unencrypted document containing customers' first names and social security numbers to her personal and her son's email addresses on March 23, 2012, in violation of corporate policy. The incident was discovered on March 27, 2012. The employee was terminated, and Cigna discontinued the document's production, enhanced safeguards, and retrained staff. Affected individuals were offered two years of credit monitoring.