Back to the register

Humana Inc.

ArchivedSubmitted 01/15/2019
State
KY
Covered entity type
Health Plan
Individuals affected
598
Business associate present
No
Type of breach
Hacking/IT Incident
Location of breached information
Other
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

From December 1, 2018, to December 3, 2018, the covered entity’s (CE) mobile app, Humana @ Home, experienced a credential stuffing attack, whereby a bad actor verified valid log-in credentials for the CE’s members. The bad actor was not able to access protected health information (PHI) on the Humana @ Home app, but instead used the verified credentials to log-in to Humana’s Go365 app, gaining potential access to 749 individuals’ names, dates of birth, addresses, provider’s names, dates of medical service, and types of medical service. Of the affected individuals, 598 were the CE’s members and the remaining 151 were employees of self-insured entities that contract with Humana to administer their insurance programs. Humana notified all these entities of the breach. To mitigate the breach, the CE deactivated the Humana @ Home app, and implemented two-step authentication on all of their apps and websites. Humana provided breach notification to HHS, the 598 affected individuals that are Humana insurance members, and to the employers of the other affected individuals. Humana did not provide media notification because there were no states in which more than 500 individuals were affected. OCR obtained assurances that the CE implemented the corrective actions listed above.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.