Metropolitan Life Insurance Company (MetLife) reported to HHS on 2017-07-19 an Unauthorized Access/Disclosure affecting 4,220 individuals. An unauthorized individual used an external phishing email to harvest account credentials from MetLife customers and non-customers, gaining access to ~4,420 online customer accounts. PHI exposed included names, addresses, health policy numbers, and account/authentication information. OCR ultimately determined the incident did not constitute a HIPAA breach as MetLife's own systems were not compromised. MetLife notified affected individuals and provided free credit monitoring. Location of breached information: Other.
Affected (this filing): 4,220