MultiPlan
Disclosed Jun 24, 20215 years ago214,956 affectedConfirmed
The business associate (BA), MultiPlan, reported that an employee was the victim of an email phishing attack affecting the protected health information (PHI) of 214,956 individuals. The PHI involved included names, addresses, email addresses, dates of birth, claims and health insurance information, and Social Security numbers. The BA notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the BA sanctioned the responsible employee, revised its policies and procedures, and implemented additional technical safeguards. All staff were retrained on email security.
What is known
| People affected | 214,956 (as reported by the organization) |
|---|---|
| Disclosed | Jun 24, 2021 |
| Happened | Dec 23, 2020 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Indiana Attorney General 2021 data breach report: MultiPlanin.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): MultiPlan (Business Associate, NY)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Indiana AGresidents of IN | Jun 24, 2021 | 1,839 |
| HHS archivetotal | Jun 24, 2021 | 214,956 |
History of this record
- 2026-09-25 · sector: other to health · backfill source
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · summary: empty to The business associate (BA), MultiPlan, reported that an employee was the victim of an email phishing attack affecting the protected health information (PHI) of 214,956 individuals. The PHI involved included names, addresses, email addresse · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.