Skip to content

Highmark

Disclosed Mar 11, 20224 years ago1,073,316 affectedConfirmed

Official notice

Highmark, the business associate (BA), reported that an employee was the subject of an email phishing scheme that compromised the protected health information (PHI) of 36,600 individuals. The PHI involved included names, addresses, birthdates, Social Security and drivers’ license numbers, diagnoses, medications, claims and financial information, and other treatment information. The BA notified HHS, affected individuals, and the media. In response to the incident, the BA provided complimentary credit monitoring services and implemented additional administrative, technical, and security safeguards. Staff were retrained on email security.

What is known

People affected1,073,316 (as reported by the organization)
DisclosedMar 11, 2022
DiscoveredDec 15, 2022
HappenedDec 13, 2022
AttackPhishing
Data exposedNames, Health, Insurance
SectorHealthcare · US
StatusConfirmed

Sources

Source
California Attorney General breach notice: Highmarkoag.ca.gov · Official notice
Washington Attorney General breach notice: Highmarkatg.wa.gov · Official notice
Notice letter filed with the Delaware DOJ: Highmarkattorneygeneral.delaware.gov · Official notice
Delaware DOJ breach notice: Highmarkattorneygeneral.delaware.gov · Official notice
HHS OCR breach report (archive, resolved): Highmark (Business Associate, PA)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalMar 11, 202267,147
HHS archivetotalJun 30, 2022511
Delaware DOJresidents of DEJul 27, 2022486
California AGresidents of CAFeb 3, 2023
Washington AGresidents of WAFeb 6, 20231,980
HHS archivetotalFeb 10, 202336,600
HHS archivetotalFeb 10, 2023239,039
Delaware DOJresidents of DEFeb 15, 2023559

Other breaches at Highmark

BreachAffected
Disclosed Mar 29, 2024Mar 29, 20242 years agoInsider6,205
Disclosed Jun 24, 2021Jun 24, 20215 years ago5,921
Disclosed Jul 8, 2014Jul 8, 201412 years agoLost or stolen device2,589
History of this record
  • 2026-09-25 · disclosed: 2022-06-30 to 2022-03-11 · backfill source
  • 2026-09-25 · disclosed: 2022-07-27 to 2022-06-30 · backfill source
  • 2026-09-25 · summary: empty to Highmark, the business associate (BA), reported that an employee was the subject of an email phishing scheme that compromised the protected health information (PHI) of 36,600 individuals. The PHI involved included names, addresses, birthdat · backfill source
  • 2026-09-25 · data_types: ["names"] to ["names","health","insurance"] · backfill source
  • 2026-09-25 · records_basis: empty to organization · backfill source
  • 2026-09-25 · records: empty to 1073316 · backfill source
  • 2026-09-25 · disclosed: 2023-02-03 to 2022-07-27 · backfill source
  • 2026-09-25 · data_types: [] to ["names"] · backfill source
  • 2026-09-25 · sector: other to health · backfill source
  • 2026-09-25 · attack: unknown to phishing · backfill source
  • 2026-09-25 · discovered: empty to 2022-12-15 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about Highmark

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.