Aetna Life Insurance Company and the affiliated covered entity (Aetna) has agreed to pay $1,000,000 to OCR and to adopt a corrective action plan to settle potential violations of the HIPAA Privacy and Security Rules. Aetna is an American managed health care company that sells traditional and consumer-directed health insurance and related services. In June 2017, Aetna submitted a breach report to OCR stating that on April 27, 2017, Aetna discovered that two web services used to display plan-related documents to health plan members allowed documents to be accessible without login credentials and subsequently indexed by various internet search engines. Aetna reported that 5,002 individuals were affected by this breach, and the protected health information (PHI) disclosed included names, insurance identification numbers, claim payment amounts, procedures service codes, and dates of service. In August 2017, Aetna submitted a breach report to OCR stating that on July 28, 2017, benefit notices were mailed to members using window envelopes. Shortly after the mailing, Aetna received complaints from members that the words "HIV medication" could be seen through the envelope's window below the
2026-09-25 · records: 5002 to 18854 · backfill source
2026-09-25 · disclosed: 2017-06-20 to 2016-11-28 · backfill source
2026-09-25 · attack: unknown to insider · backfill source
2026-09-25 · data_types: ["names"] to ["names","health"] · backfill source
2026-09-25 · records_basis: empty to hhs · backfill source
2026-09-25 · records: empty to 5002 · backfill source
2026-09-25 · summary: empty to Aetna Life Insurance Company and the affiliated covered entity (Aetna) has agreed to pay $1,000,000 to OCR and to adopt a corrective action plan to settle potential violations of the HIPAA Privacy and Security Rules. Aetna is an American ma · backfill source
2026-09-25 · sector: other to insurance · backfill source
2026-09-25 · data_types: [] to ["names"] · backfill source
2026-09-25 · disclosed: 2017-07-10 to 2017-06-20 · backfill source