Highmark, the business associate (BA), reported that an employee was the subject of an email phishing scheme that compromised the protected health information (PHI) of 36,600 individuals. The PHI involved included names, addresses, birthdates, Social Security and drivers’ license numbers, diagnoses, medications, claims and financial information, and other treatment information. The BA notified HHS, affected individuals, and the media. In response to the incident, the BA provided complimentary credit monitoring services and implemented additional administrative, technical, and security safeguards. Staff were retrained on email security.
2026-09-25 · disclosed: 2022-06-30 to 2022-03-11 · backfill source
2026-09-25 · disclosed: 2022-07-27 to 2022-06-30 · backfill source
2026-09-25 · summary: empty to Highmark, the business associate (BA), reported that an employee was the subject of an email phishing scheme that compromised the protected health information (PHI) of 36,600 individuals. The PHI involved included names, addresses, birthdat · backfill source
2026-09-25 · data_types: ["names"] to ["names","health","insurance"] · backfill source
2026-09-25 · records_basis: empty to organization · backfill source
2026-09-25 · records: empty to 1073316 · backfill source
2026-09-25 · disclosed: 2023-02-03 to 2022-07-27 · backfill source
2026-09-25 · data_types: [] to ["names"] · backfill source
2026-09-25 · sector: other to health · backfill source
2026-09-25 · attack: unknown to phishing · backfill source
2026-09-25 · discovered: empty to 2022-12-15 · backfill source