- State
- KY
- Covered entity type
- Health Plan
- Individuals affected
- 863
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), Humana, discovered that from March 15, 2019, to May 1, 2019, a programming error in its Go365 mobile application allowed some Go365 participants to see other participants’ protected health information. Go365 is a reward and incentive program that helps participants track and reach health goals. Humana determined that 863 individuals were affected, 357 of whom are Humana insurance members. The other 486 affected individuals are employees of self-insured entities that contract with Humana to administer their insurance programs. Humana formally notified all these entities of the breach (a total of 179 employers). The types of protected health information involved in the breach included participants' names, addresses, email addresses, identification numbers, biometric screening information, and other wellness information. Following the breach, Humana deployed two updates to the Go365 application and fixed the programming error and initiated ongoing monitoring to ensure the fix was effective. Humana provided breach notification to HHS, the affected individuals that are Humana insurance members, and to the employers of the other affected individuals. Humana did not provide media notification because there were no states in which more than 500 individuals were affected. OCR obtained assurances that Humana implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.