- State
- PA
- Covered entity type
- Health Plan
- Individuals affected
- 511
- Business associate present
- Yes
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), Highmark, reported that its business associate (BA) experienced a cybersecurity incident that affected the protected health information (PHI) of 511 individuals. The PHI involved included names and medication information. The CE and its BA notified affected individuals; the CE notified HHS. In its mitigation efforts, the CE implemented new administrative and technical safeguards to better protect its PHI.
Change history
- 9/23/2026Added to OCR's archive list
Source: U.S. Department of Health and Human Services, Office for Civil Rights, Breach Portal. Records are reproduced as published; entity names and figures are OCR's.