BLUE CROSS OF IDAHO HEALTH SERVICE, INC.
ent_019e229a883de8fe6e5726240944d0cc
Disclosures
4
State AG · HHS OCR · 1 jurisdiction
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
6,045
nationwide · HHS OCR ID
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- BLUE CROSS OF IDAHO HEALTH SERVICE, INC.
- Normalized
- blue cross of idaho health service— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- C3OAIV5QRQL8RHJV1W97
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- Idaho State AGas victim2021-12-08
Blue Cross of Idaho notified the Idaho AG that an external review vendor experienced a data breach on Nov 9, 2021. 22 members affected (10 in Idaho). SSNs likely involved. Vendor recovered data; no misuse found. Vendor handling notifications and credit monitoring.
- Idaho State AGas victim2021-04-22
Blue Cross of Idaho submitted a supplemental notice to the Idaho Attorney General regarding a phishing attack on a broker. The incident resulted in unauthorized access to an employee's email account. The broker is notifying members and offering credit monitoring.
- Idaho State AGas reporting2021-03-19
Supplemental notice to Idaho AG regarding a phishing attack on insurance broker Armfield, Harrison & Thomas (AHT) on Dec 4, 2020. AHT discovered the breach on Dec 8, 2020. Compromised data included names, addresses, DOB, medical info, health insurance info, other gov ID, and financial account numbers. Blue Cross of Idaho is reporting on behalf of AHT.
- IDAHOHHS OCRas victim2019-04-19
Blue Cross of Idaho Health Service, Inc. reported to HHS on April 19, 2019, that an unauthorized individual impersonated a healthcare provider to gain access to its provider web portal, affecting 6,045 individuals. The actor accessed names, health insurance, clinical, and financial information and attempted to reroute payments to a fraudulent bank account. In response, the entity stopped the fraudulent payment, initiated an investigation, revised policies, retrained staff on social engineering, and offered three years of credit monitoring to affected individuals.