Skip to content

Aetna

Disclosed Jul 27, 201016 years ago6,372 affectedConfirmed

Official notice

Aetna notified all possibly affected individuals of the breach, filed a breach report with OCR, commenced an investigation to identify and correct the root cause of the issue; the coding changes that were causing the breach were removed from IPS via Aetna's emergency Change Management procedures to prevent any further exposure while the problem was analyzed; once the specific code that conflicted with its proxy server settings was identified as the root cause of the breach, it was removed. Also, in an effort to mitigate any harm as a result of the breach, Aetna offered all affected individuals one year of free credit monitoring, and the notification letters included a toll-free number which was established specifically to answer questions related to this incident. \

What is known

People affected6,372 (as reported to HHS)
DisclosedJul 27, 2010
AttackInsider
Data exposedNames, Health
SectorInsurance · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Aetna (Health Plan, CT)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalJul 27, 20106,372
HHS archivetotalNov 7, 20102,345

Other breaches at Aetna

BreachAffected
Disclosed Feb 27, 2026Feb 277 months agoInsider775
Disclosed Jul 27, 2022Jul 27, 20224 years ago326K
Disclosed Dec 10, 2020Dec 10, 20205 years ago484K
Disclosed Aug 29, 2017Aug 29, 20179 years agoHacking12K
Disclosed Nov 28, 2016Nov 28, 20169 years agoInsider19K
Web site breach may have exposed SSNs of 65,000 Aetna employeesMay 28, 200917 years agoHackingUnverified65K
History of this record
  • 2026-09-25 · records: 2345 to 6372 · backfill source
  • 2026-09-25 · disclosed: 2010-11-07 to 2010-07-27 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Aetna

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.