Skip to content

Cigna

Disclosed Oct 10, 20187 years ago3,720 affectedConfirmed

Official notice

The covered entity (CE), Cigna, reported that its business associate (BA), Availity had fraudulent provider accounts on its provider portal. This breach affected 3,720 individuals and the protected health information (PHI) involved included names, dates of birth, addresses, and health insurance information. Cigna notified HHS, affected individuals, and the media. Cigna also provided two years of complimentary identity protection services.

What is known

People affected3,720 (as reported to HHS)
DisclosedOct 10, 2018
DiscoveredSep 5, 2018
HappenedSep 5, 2018
AttackHacking
Data exposedNames, Health
SectorInsurance · US
StatusConfirmed

Sources

Source
Oregon DOJ breach notice: Cignajustice.oregon.gov · Official notice
HHS OCR breach report (archive, resolved): Cigna (Health Plan, CT)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
Oregon DOJresidents of OROct 10, 2018
HHS archivetotalOct 10, 20183,500
HHS archivetotalMay 16, 20193,720

Other breaches at Cigna

BreachAffected
Disclosed May 24, 2017May 24, 20179 years ago267
Disclosed Apr 9, 2014Apr 9, 201412 years agoLost or stolen device527
History of this record
  • 2026-09-25 · sector: other to insurance · backfill source
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 3720 · backfill source
  • 2026-09-25 · summary: empty to The covered entity (CE), Cigna, reported that its business associate (BA), Availity had fraudulent provider accounts on its provider portal. This breach affected 3,720 individuals and the protected health information (PHI) involved included · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Oregon DOJ), confirmed by Oregon DOJ. Record counts are as reported. Not legal advice.

Everything about Cigna

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.