Highmark Inc Data Breach
Highmark Inc. Email System Compromised in Hacking Incident
What happened in the Highmark Inc data breach?
The Highmark Inc data breach was reported on February 10, 2023 and affected 36,600 individuals. The breach type was Hacking/IT Incident involving Email. This breach occurred in Pennsylvania. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Highmark Inc Breach Details
On February 10, 2023, Highmark Inc., a major Pennsylvania-based health insurance company, reported a significant data breach affecting 36,600 individuals. The breach resulted from unauthorized access to the company's email systems through a hacking incident, exposing sensitive health information and personal data to threat actors. This incident represents a substantial security failure in one of the organization's critical communication infrastructure components, which typically serves as a central repository for patient records, claims information, and other protected health information (PHI).
Company Response
Highmark Inc. discovered the unauthorized access to its email systems and initiated an immediate investigation to determine the scope and nature of the compromise. Upon discovery, the organization engaged in forensic analysis to identify which email accounts were accessed, what data may have been exposed, and the methods used by the attackers. The company notified affected individuals in accordance with HIPAA Breach Notification Rule requirements, which mandate notification without unreasonable delay and no later than 60 calendar days after discovery of a breach. Highmark also reported the incident to the U.S. Department of Health and Human Services Office for Civil Rights (OCR), as required by federal law for breaches affecting 500 or more residents of a state or jurisdiction.
Specific Details
The breach occurred within Highmark's email infrastructure, which typically contains a wide range of sensitive communications including patient health records, insurance claims, eligibility information, and correspondence between healthcare providers and insurance personnel. Email systems in healthcare organizations often serve as repositories for unencrypted PHI, making them attractive targets for cybercriminals. The hacking incident suggests that threat actors exploited vulnerabilities in the email system's security controls, potentially through methods such as credential compromise, phishing attacks targeting employees, exploitation of unpatched software vulnerabilities, or misconfigured access controls. Email-based breaches are particularly concerning because they may provide attackers with access to historical communications and stored documents spanning months or years, significantly expanding the volume of potentially exposed data.
Organizational Context
Highmark Inc. is one of the largest health insurance companies in the United States, operating primarily in Pennsylvania, Delaware, and West Virginia. The organization serves millions of members through various insurance products including commercial health insurance, Medicare Advantage plans, and Medicaid coverage. As a major health insurance company, Highmark processes claims, maintains member records, and coordinates care across a vast network of healthcare providers. The organization's infrastructure supports complex operations including claims processing, member services, provider communications, and administrative functions. The scale of Highmark's operations means that any security incident affecting its systems has the potential to impact hundreds of thousands of individuals, making strong cybersecurity controls essential to protecting member privacy.
Number of People Affected
The breach notification indicates that 36,600 individuals were affected by the unauthorized access to Highmark's email systems. These individuals likely include current and former health insurance members whose information was contained within compromised email accounts. The affected population may also include healthcare providers, employees, and other individuals who had communicated with Highmark through the compromised email infrastructure. The notification was submitted to the HHS Office for Civil Rights on February 10, 2023, triggering the federal breach notification requirements and public disclosure through the HHS Breach Portal.
Personal Information Involved
Based on the nature of email systems within health insurance organizations, the compromised data likely included multiple categories of protected health information and personally identifiable information. Potential data types exposed may include: member names and contact information (addresses, phone numbers, email addresses); Social Security numbers or other government-issued identification numbers; health insurance member identification numbers and policy information; medical history and health conditions; claims information and healthcare service details; financial information including bank account numbers or payment card data; dates of birth and demographic information; and healthcare provider information and communications. The specific combination of data exposed would depend on which email accounts were compromised and what documents or communications those accounts contained.
Patient Impact and Notification
Individuals affected by this breach face potential risks associated with the exposure of their health information and personal identifiers. Highmark Inc. was required to provide written notification to all affected individuals describing the nature of the breach, the types of information exposed, the steps the company was taking to investigate the incident, and recommended actions individuals should take to protect themselves. The notification also included information about credit monitoring services or identity theft protection resources that Highmark may have offered to affected individuals. Notification letters were required to be sent without unreasonable delay and no later than 60 days after discovery of the breach, in compliance with HIPAA requirements.
Industry Context and HIPAA Implications
This incident highlights ongoing vulnerabilities in healthcare cybersecurity infrastructure. Email systems remain a common attack vector in healthcare breaches, accounting for a significant percentage of reported incidents annually. The HIPAA Security Rule requires covered entities and business associates to implement administrative, physical, and technical safeguards to protect electronic protected health information (ePHI). These safeguards must include access controls, encryption, audit controls, and integrity controls. The fact that a major health insurance company experienced a successful hacking incident affecting its email systems suggests potential gaps in the implementation or maintenance of these required security controls. Healthcare organizations are increasingly targeted by sophisticated threat actors seeking valuable health information and personal identifiers that can be used for identity theft, insurance fraud, or sold on the dark web. The healthcare sector continues to experience a high volume of breaches, with email compromise incidents representing a persistent and evolving threat. Organizations must maintain vigilant monitoring, implement multi-factor authentication, conduct regular security awareness training, and maintain current patch management practices to mitigate these risks.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Highmark Inc Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries; consider placing a fraud alert or credit freeze to prevent unauthorized credit applications
Review healthcare claims and explanation of benefits (EOB) statements carefully for any services you did not receive; contact Highmark immediately if you identify fraudulent claims or unauthorized medical services
Change passwords for any online accounts associated with Highmark or your health insurance, using strong, unique passwords; enable multi-factor authentication where available
Remain vigilant for phishing emails, phone calls, or text messages claiming to be from Highmark or healthcare providers; do not click links or provide personal information in response to unsolicited communications; verify requests by contacting Highmark directly using official contact information
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Pennsylvania Breaches
Search all breaches reported in Pennsylvania
Were You Affected?
Patients affected by large healthcare data breaches may be eligible for compensation through class action lawsuits.
Learn about data breach lawsuits