Skip to content

Aetna

Disclosed Nov 28, 20169 years ago18,854 affectedConfirmed

Official notice

Aetna Life Insurance Company and the affiliated covered entity (Aetna) has agreed to pay $1,000,000 to OCR and to adopt a corrective action plan to settle potential violations of the HIPAA Privacy and Security Rules. Aetna is an American managed health care company that sells traditional and consumer-directed health insurance and related services. In June 2017, Aetna submitted a breach report to OCR stating that on April 27, 2017, Aetna discovered that two web services used to display plan-related documents to health plan members allowed documents to be accessible without login credentials and subsequently indexed by various internet search engines. Aetna reported that 5,002 individuals were affected by this breach, and the protected health information (PHI) disclosed included names, insurance identification numbers, claim payment amounts, procedures service codes, and dates of service. In August 2017, Aetna submitted a breach report to OCR stating that on July 28, 2017, benefit notices were mailed to members using window envelopes. Shortly after the mailing, Aetna received complaints from members that the words "HIV medication" could be seen through the envelope's window below the

What is known

People affected18,854 (as reported to HHS)
DisclosedNov 28, 2016
DiscoveredApr 24, 2017
HappenedFeb 1, 2017
AttackInsider
Data exposedNames, Health
SectorInsurance · US
StatusConfirmed

Sources

Source
Oregon DOJ breach notice: Aetnajustice.oregon.gov · Official notice
Maine Attorney General breach notice archive: Aetnamaine.gov · Official notice
HHS OCR breach report (archive, resolved): Aetna (Health Plan, CT)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalNov 28, 201618,854
Maine AGresidents of MEJun 20, 2017
HHS archivetotalJun 20, 20175,002
Oregon DOJresidents of ORJul 10, 20175,002

Other breaches at Aetna

BreachAffected
Disclosed Feb 27, 2026Feb 277 months agoInsider775
Disclosed Jul 27, 2022Jul 27, 20224 years ago326K
Disclosed Dec 10, 2020Dec 10, 20205 years ago484K
Disclosed Aug 29, 2017Aug 29, 20179 years agoHacking12K
Disclosed Jul 27, 2010Jul 27, 201016 years agoInsider6,372
Web site breach may have exposed SSNs of 65,000 Aetna employeesMay 28, 200917 years agoHackingUnverified65K
History of this record
  • 2026-09-25 · records: 5002 to 18854 · backfill source
  • 2026-09-25 · disclosed: 2017-06-20 to 2016-11-28 · backfill source
  • 2026-09-25 · attack: unknown to insider · backfill source
  • 2026-09-25 · data_types: ["names"] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 5002 · backfill source
  • 2026-09-25 · summary: empty to Aetna Life Insurance Company and the affiliated covered entity (Aetna) has agreed to pay $1,000,000 to OCR and to adopt a corrective action plan to settle potential violations of the HIPAA Privacy and Security Rules. Aetna is an American ma · backfill source
  • 2026-09-25 · sector: other to insurance · backfill source
  • 2026-09-25 · data_types: [] to ["names"] · backfill source
  • 2026-09-25 · disclosed: 2017-07-10 to 2017-06-20 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Oregon DOJ), confirmed by Oregon DOJ. Record counts are as reported. Not legal advice.

Everything about Aetna

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.