Skip to content

Humana

Disclosed Nov 21, 20178 years ago6,836 affectedConfirmed

Official notice

On August 31, 2017, the covered entity (CE), Humana, Inc., discovered that its business associate (BA), Real Time Health Quotes, mistakenly exposed the electronic protected health information (ePHI) of 5,764 individuals stored through a cloud service provider. The types of PHI involved in the breach included names, birthdates, addresses, driver’s license numbers, social security numbers, financial information, and medical information. In response to the breach, the CE and BA investigated the cause and found a misconfiguration in the BA's data backup process. The BA ensured the problem was remedied on September 1, 2017, and updated its policies and technical safeguards to prevent similar problems in the future. The CE provided breach notification to HHS. The BA provided breach notification to individuals and media outlets on November 17, 2017. The delay in sending notification was attributed to the time it took to sort through the exposed information. The content of the notification letters comply with HIPAA requirements. OCR obtained documented assurances that the CE and BA implemented the voluntary corrective actions listed above.

What is known

People affected6,836 (as reported by the organization)
DisclosedNov 21, 2017
HappenedMay 30, 2018
AttackInsider
Data exposedNames, Health, Biometrics, Social Security numbers
SectorFinance · US
StatusConfirmed

Sources

Source
California Attorney General breach notice: Humanaoag.ca.gov · Official notice
Indiana Attorney General 2018 data breach report: Humanain.gov · Official notice
Maine Attorney General breach notice archive: Humanamaine.gov · Official notice
HHS OCR breach report (archive, resolved): Humana (Health Plan, KY)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalNov 21, 20175,764
Indiana AGresidents of INJun 4, 201872
Maine AGresidents of MEJun 4, 201813
Indiana AGresidents of INJun 21, 20186
Maine AGresidents of MEJun 22, 20181
Maine AGresidents of MEAug 27, 20182
Indiana AGresidents of INAug 28, 20189
Indiana AGresidents of INSep 21, 20184
Indiana AGresidents of INSep 26, 20181
California AGresidents of CAJan 3, 2019

Other breaches at Humana

BreachAffected
Disclosed Apr 29, 2025Apr 29, 20251 year ago16K
Disclosed Jun 15, 2023Jun 15, 20233 years agoHacking13K
Disclosed Sep 9, 2021Sep 9, 20215 years agoHacking23K
Disclosed Aug 19, 2020Aug 19, 20206 years agoLost or stolen device65K
Disclosed Dec 31, 2018Dec 31, 20187 years agoInsider5,569
Disclosed May 23, 2014May 23, 201412 years agoUnknown
History of this record
  • 2026-09-25 · attack: unknown to insider · backfill source
  • 2026-09-25 · disclosed: 2018-06-04 to 2017-11-21 · backfill source
  • 2026-09-25 · summary: empty to On August 31, 2017, the covered entity (CE), Humana, Inc., discovered that its business associate (BA), Real Time Health Quotes, mistakenly exposed the electronic protected health information (ePHI) of 5,764 individuals stored through a clo · backfill source
  • 2026-09-25 · data_types: ["names","health","biometrics"] to ["names","health","biometrics","ssn"] · backfill source
  • 2026-09-25 · data_types: [] to ["names","health","biometrics"] · backfill source
  • 2026-09-25 · records: 249 to 6836 · backfill source
  • 2026-09-25 · disclosed: 2018-06-21 to 2018-06-04 · backfill source
  • 2026-09-25 · sector: other to finance · backfill source
  • 2026-09-25 · records_basis: empty to organization · backfill source
  • 2026-09-25 · records: empty to 249 · backfill source
  • 2026-09-25 · disclosed: 2019-01-03 to 2018-06-21 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about Humana

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.