Skip to content

Highmark

Disclosed Mar 29, 20242 years ago6,205 affectedConfirmed

Official notice

Highmark, the covered entity (CE), reported that an employee mailed the protected health information (PHI) of 6,205 individuals to outdated addresses. The PHI involved included names, addresses, dates of birth, member identification number, diagnoses, medications, and other treatment and financial information. The CE notified HHS, impacted individuals, and the media. In its mitigation efforts, the CE implemented additional administrative and technical safeguards to better protect its sensitive data. Staff were retrained.

What is known

People affected6,205 (as reported to HHS)
DisclosedMar 29, 2024
AttackInsider
Data exposedNames, Health
SectorInsurance · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Highmark (Health Plan, PA)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalMar 29, 20246,205

Other breaches at Highmark

BreachAffected
Disclosed Mar 11, 2022Mar 11, 20224 years agoPhishing1.1M
Disclosed Jun 24, 2021Jun 24, 20215 years ago5,921
Disclosed Jul 8, 2014Jul 8, 201412 years agoLost or stolen device2,589
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Highmark

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.