Wellpoint, Inc.
ent_019e10bbe27d1632d8e420993f945170
Disclosures
5
State AG · HHS OCR · HHS OCR enforcement · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
31,700
nationwide · HHS OCR IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Wellpoint, Inc.
- Normalized
- wellpoint— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
- Corporate parent
- Elevance Health, Inc.— per SEC Exhibit 21 filing
Disclosure history (5)newest first
- Texas State AGas victim2026-06-30
Wellpoint based in Indianapolis, Indiana, a insurance services entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-03-02 and reported on 2026-06-30. 24 Texas residents were affected. 708 individuals affected in total. Types of information involved: Name of individual;Medical Information;Health Insurance Information;Other;Date of Birth.
- Washington State AGas reporting2026-06-02
Wellpoint Washington, Inc. reported a phishing incident affecting 12,017 Washington residents. The breach occurred June 24-July 2, 2025, involving unauthorized access to an email account via a phishing attack by business associate Clinics of Washington. Wellpoint discovered the incident on March 2, 2026. Exposed data included PHI, SSNs, DOBs, and driver's licenses. Remediation included credit monitoring services.
- INDIANAHHS OCRas victim2025-10-07
HHS OCR breach portal entry: Wellpoint, Inc. (Indiana, Business Associate) reported a Hacking/IT Incident affecting a Network Server, impacting 579 individuals. Submitted 2025-10-07. No narrative description provided in the portal row.
- FEDERALHHS OCR enforcementas victim2013-07-11
WellPoint Inc. settled potential HIPAA Privacy and Security Rule violations for $1.7 million. OCR found WellPoint failed to implement appropriate administrative and technical safeguards, including policies for authorizing access to an online application database, performing technical evaluations for software upgrades, and verifying access to electronic protected health information (ePHI). This resulted in the impermissible disclosure of ePHI for 612,402 individuals.
- INDIANAHHS OCRas victim2010-07-30
WellPoint, Inc. reported to HHS on 2010-07-30 a Hacking/IT Incident affecting 31700 individuals. Breached information located on Network Server.