The covered entity (CE), Cigna, reported that its business associate (BA), Availity had fraudulent provider accounts on its provider portal. This breach affected 3,720 individuals and the protected health information (PHI) involved included names, dates of birth, addresses, and health insurance information. Cigna notified HHS, affected individuals, and the media. Cigna also provided two years of complimentary identity protection services.
2026-09-25 · sector: other to insurance · backfill source
2026-09-25 · attack: unknown to hacking · backfill source
2026-09-25 · data_types: [] to ["names","health"] · backfill source
2026-09-25 · records_basis: empty to hhs · backfill source
2026-09-25 · records: empty to 3720 · backfill source
2026-09-25 · summary: empty to The covered entity (CE), Cigna, reported that its business associate (BA), Availity had fraudulent provider accounts on its provider portal. This breach affected 3,720 individuals and the protected health information (PHI) involved included · backfill source