Skip to content

Aflac

Disclosed May 20, 201610 years ago930 affectedConfirmed

Official notice

Due to a vendor error, the covered entity (CE), Aflac, erroneously sent correspondence containing protected health information (PHI) to the wrong customers, affecting 930 policyholders. The types of PHI included names, policy numbers, types of coverage, employee numbers, and premium amounts, depending on the type of correspondence mailed. In addition, six policyholders’ social security numbers were potentially comprised. In response to the breach, the CE retrained employees and revised its impermissible disclosures and safeguard policies. Additionally, the CE sanctioned the manager who led the address standardization project and terminated its contract with all third party vendors and contractors involved in the breach. The CE provided breach notification to HHS, and affected individuals. Media notice was not required because the incident did not involve more than 500 residents in any particular state. OCR obtained assurances that the CE implemented the corrective actions listed above.

What is known

People affected930 (as reported to HHS)
DisclosedMay 20, 2016
HappenedDec 4, 2016
AttackInsider
Data exposedNames, Health
SectorInsurance · US
StatusConfirmed

Sources

Source
Indiana Attorney General 2016 data breach report: AFLACin.gov · Official notice
HHS OCR breach report (archive, resolved): Aflac (Health Plan, GA)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalMay 20, 2016930
Indiana AGresidents of INDec 22, 2016132

Other breaches at Aflac

BreachAffected
Aflac hack exposes SSNs and health data of 22.65 million peopleJun 20, 20251 year agoHacking23M
Disclosed Mar 1, 2021Mar 1, 20215 years ago2,635
Disclosed Dec 16, 2019Dec 16, 20196 years agoInsider1,601
Disclosed May 29, 2018May 29, 20188 years agoHacking10K
Disclosed May 15, 2015May 15, 201511 years agoInsider6,166
Disclosed Jan 15, 2014Jan 15, 201412 years ago1
History of this record
  • 2026-09-25 · attack: unknown to insider · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: organization to hhs · backfill source
  • 2026-09-25 · records: 158 to 930 · backfill source
  • 2026-09-25 · disclosed: 2016-12-22 to 2016-05-20 · backfill source
  • 2026-09-25 · summary: empty to Due to a vendor error, the covered entity (CE), Aflac, erroneously sent correspondence containing protected health information (PHI) to the wrong customers, affecting 930 policyholders. The types of PHI included names, policy numbers, types · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.

Everything about Aflac

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.