Skip to content

Highmark

Disclosed Jul 8, 201412 years ago2,589 affectedConfirmed

Official notice

Health profile and care summaries and corresponding cover letters were incorrectly mailed to senior members of the covered entity (CE), Highmark Health, and their physicians. The protected health information involved in the breach included the names, addresses, telephone numbers, dates of birth, unique medical identifiers (UMI), gender, medications, and health information of 2,589 individuals. The CE provided breach notification to HHS, the media, and affected individuals. Following the breach, the CE issued a new UMI to each member impacted by the incident. The CE determined that a process failure by an employee was the root cause for the incorrect mailing and subsequently terminated the employee. As a result of OCR's investigation, the CE instituted new quality review procedures for mailings and retrained employees on its privacy practices and departmental policies, processes and procedures. OCR obtained details of the CE's revised policies on its health profiles to assure they include only the minimum necessary information.

What is known

People affected2,589 (as reported to HHS)
DisclosedJul 8, 2014
AttackLost or stolen device
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Highmark (Business Associate, PA)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalJul 8, 20142,589

Other breaches at Highmark

BreachAffected
Disclosed Mar 29, 2024Mar 29, 20242 years agoInsider6,205
Disclosed Mar 11, 2022Mar 11, 20224 years agoPhishing1.1M
Disclosed Jun 24, 2021Jun 24, 20215 years ago5,921
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Highmark

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.