Between Dec. 13 and Dec. 15, a hacker got access to files containing members’ data after sending a malicious phishing link to an employee’s email, according to the statement.
The health system said the compromised data may have included such information as procedures, prescriptions, passport numbers, Social Security numbers and financial information. The organization said it isn’t aware of any of the data being misused.
“Highmark takes the security of member information seriously and has implemented a robust action plan to bolster employee training on phishing email threats to prevent future incidents of this nature,” the statement said.
The breach was first reported Feb. 5 by DataBreaches.net.
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.