Skip to content

Unum Group

Disclosed Jan 24, 20197 years ago532 affectedConfirmed

Official notice

The covered entity (CE), Unum Group, reported that an employee was the victim of an email phishing scheme. The protected health information (PHI) involved included names, addresses, dates of birth, Social Security numbers, health diagnoses, and employer information. This breach affected 532 individuals. The CE retained legal counsel and hired forensic investigators to assist with the investigation. The CE provided breach notification to HHS and affected individuals. In addition, Unum deleted the phishing email from mailboxes, forced password resets, updated and completed a risk analysis, implemented multi-factor authentication, reduced email retention, blocked suspicious websites, and provided supplemental HIPAA training to its workforce. OCR provided the CE with technical assistance regarding timely breach notification. OCR obtained assurances that the CE met its notification requirements and implemented the corrective actions noted above.

What is known

People affected532 (as reported to HHS)
DisclosedJan 24, 2019
DiscoveredOct 10, 2019
HappenedOct 1, 2019
AttackHacking
Data exposedNames, Health
SectorFinance · US
StatusConfirmed

Sources

Source
Oregon DOJ breach notice: Unum Groupjustice.oregon.gov · Official notice
HHS OCR breach report (archive, resolved): Unum Group (Health Plan, TN)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalJan 24, 2019532
Oregon DOJresidents of ORDec 30, 20198,887

Other breaches at Unum Group

BreachAffected
Disclosed Aug 3, 2023Aug 3, 20233 years agoHacking651K
Disclosed Jan 28, 2022Jan 28, 20224 years agoHacking34K
Disclosed Jan 10, 2014Jan 10, 201412 years ago50
History of this record
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 532 · backfill source
  • 2026-09-25 · disclosed: 2019-12-30 to 2019-01-24 · backfill source
  • 2026-09-25 · summary: empty to The covered entity (CE), Unum Group, reported that an employee was the victim of an email phishing scheme. The protected health information (PHI) involved included names, addresses, dates of birth, Social Security numbers, health diagnoses, · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Oregon DOJ), confirmed by Oregon DOJ. Record counts are as reported. Not legal advice.

Everything about Unum Group

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.