Company Details
bcbst
4,877
40,691
524
http://www.bcbst.com
0
BLU_4706375
In-progress

BlueCross BlueShield of Tennessee Company CyberSecurity Posture
http://www.bcbst.comAs Tennessee's largest health plan, we've been helping Tennesseans find their own unique paths to good health for more than 70 years. More than that, we're your neighbors and friends – fellow Tennesseans with deep roots of caring tradition, a focused approach to physical, financial and community good health for today, and a bright outlook for an even healthier tomorrow. Our mission is simple: peace of mind through better health. We're an independent, not-for-profit, locally governed health plan company – meaning we live and work alongside our Tennessee business customers and plan members. Our 6,000 employees across the state have built our strong reputation for integrity, excellent service and community leadership. But we are also part of the BlueCross BlueShield Association, a nationwide association of health care plans. Because of this, our plan members have access to the same quality health benefits while traveling or living out of state that they have while in Tennessee. © 2018 BlueCross BlueShield of Tennessee, Inc., an Independent Licensee of the BlueCross BlueShield Association.
Company Details
bcbst
4,877
40,691
524
http://www.bcbst.com
0
BLU_4706375
In-progress
Between 700 and 749

BBT Global Score (TPRM)XXXX

Description: On December 18, 2020, the Maine Office of the Attorney General reported a data breach involving BlueCross BlueShield of Tennessee, Inc. The breach, which occurred from June 24 to July 1, 2020, was due to unauthorized access to email accounts of their vendor, EyeMed Vision Care, potentially affecting 1,340 individuals, including 3 Maine residents, with Social Security numbers being among the compromised information. BlueCross notified affected Maine residents on December 9, 2020.
Description: Some member reports from BlueCross BlueShield of Tennessee were delivered to group benefit administrators due to a computer error. By mistakenly delivering a report titled the June 2017 Future Termination of Dependent Coverage, 657 employers that have accounts with BCBST obtained information intended for other businesses. The report contained information on 2,100 members, including their names, birthdates, plan types, dates of coverage, and member identification numbers. The compromised data did not include social security numbers, addresses, bank or financial information, or health information. On July 5, BCBST became aware of the intrusion. The reports were sent to companies, who were instructed to delete them and certify their destruction with the insurance. People whose information was compromised were notified with a letter and offered a free identity protection service for up to two years.


No incidents recorded for BlueCross BlueShield of Tennessee in 2025.
No incidents recorded for BlueCross BlueShield of Tennessee in 2025.
No incidents recorded for BlueCross BlueShield of Tennessee in 2025.
BBT cyber incidents detection timeline including parent company and subsidiaries

As Tennessee's largest health plan, we've been helping Tennesseans find their own unique paths to good health for more than 70 years. More than that, we're your neighbors and friends – fellow Tennesseans with deep roots of caring tradition, a focused approach to physical, financial and community good health for today, and a bright outlook for an even healthier tomorrow. Our mission is simple: peace of mind through better health. We're an independent, not-for-profit, locally governed health plan company – meaning we live and work alongside our Tennessee business customers and plan members. Our 6,000 employees across the state have built our strong reputation for integrity, excellent service and community leadership. But we are also part of the BlueCross BlueShield Association, a nationwide association of health care plans. Because of this, our plan members have access to the same quality health benefits while traveling or living out of state that they have while in Tennessee. © 2018 BlueCross BlueShield of Tennessee, Inc., an Independent Licensee of the BlueCross BlueShield Association.


Bankers Life® focuses on the insurance and investment needs of middle-income Americans who are near or in retirement. The Bankers Life brand is part of CNO Financial Group, Inc. (NYSE: CNO), whose companies provide insurance and wealth management solutions that help protect the health and retirement

CNO Financial Group, Inc. (NYSE: CNO) secures the future of middle-income America. CNO provides life and health insurance, annuities, financial services, and workforce benefits solutions through our family of brands, including Bankers Life, Colonial Penn, Optavise and Washington National. Our cus

Hi, we’re HUB. We advise businesses and individuals on how to reach their goals. When you partner with us, you’re at the center of a vast network of risk, insurance, employee benefits, retirement and wealth management specialists that bring clarity to a changing world with tailored solutions and un

The Swiss Re Group is a leading wholesale provider of reinsurance, insurance and other insurance-based forms of risk transfer. Dealing direct and working through brokers, its global client base consists of insurance companies, mid-to-large-sized corporations and public sector clients. From standard

FWD Group (1828.HK) is a pan-Asian life and health insurance business that serves approximately 34 million customers across 10 markets, including BRI Life in Indonesia. FWD’s customer-led and tech-enabled approach aims to deliver innovative propositions, easy-to-understand products and a simpler ins

Somos la empresa aseguradora multirramo 100% mexicana de mayor experiencia y solidez de nuestro país. Por más de 116 años hemos protegido a las familias mexicanas, respaldando sus sueños, historias, emociones y vivencias. Estamos orgullosos de formar parte de uno de los conglomerados empresariales

SURA es una compañía que integra en diferentes empresas soluciones en seguros y seguridad social. Su marca se presenta a los clientes como Seguros SURA, ARL SURA y EPS SURA. Existen otras marcas y empresas, especialmente de prestación de servicios, que hacen parte de la Compañía. Nuestra experienc

The Life Insurance Business in Pakistan was nationalized in March 1972. Initially, the Life Insurance business of 32 Insurance Companies was merged and placed under three Beema Units named “A”, “B” and “C” Beema Units. However, later these Beema Units were merged, and effective November 1, 1972, the

Listening. Understanding. Delivering. At Prudential Indonesia we deliver excellence by consistently innovating, creating new opportunities and growing our business to cater all of our customers' needs. With a vision of becoming truly world class, Prudential Indonesia provides quality services and
.png)
Nov 21st, 2025 - Healthcare workers are becoming increasingly important in fighting off potential cyberattacks.
Conduent is facing a growing wave of federal class action lawsuits after a massive data breach exposed the personal and health information...
In 2023, 725 data breaches were reported to OCR and across those breaches, more than 133 million records were exposed or impermissibly disclosed.
In July, Wacker Chemical Corp. announced it would lay off 90 workers at its polysilicon plant in Bradley County, and a maker of asphalt...
At least 150 employees in Chattanooga will be phased out of their jobs with BlueCross Blue Shield of Tennessee this month.
Summit Medical Group is not planning to renew its contract with BlueCross BlueShield of Tennessee (BCBST) after it says they have been...
Compilation of cyberattacks by organization type and number of records compromised.
Strauss Borrelli PLLC, a leading class action law firm, is investigating BlueCross BlueShield of Tennessee in Chattanooga, Tennessee...
Explore the top tech companies in Memphis, 2025. Discover diverse opportunities and innovation in FedEx, St. Jude, PathAI, and more.

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of BlueCross BlueShield of Tennessee is http://www.bcbst.com.
According to Rankiteo, BlueCross BlueShield of Tennessee’s AI-generated cybersecurity score is 735, reflecting their Moderate security posture.
According to Rankiteo, BlueCross BlueShield of Tennessee currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, BlueCross BlueShield of Tennessee is not certified under SOC 2 Type 1.
According to Rankiteo, BlueCross BlueShield of Tennessee does not hold a SOC 2 Type 2 certification.
According to Rankiteo, BlueCross BlueShield of Tennessee is not listed as GDPR compliant.
According to Rankiteo, BlueCross BlueShield of Tennessee does not currently maintain PCI DSS compliance.
According to Rankiteo, BlueCross BlueShield of Tennessee is not compliant with HIPAA regulations.
According to Rankiteo,BlueCross BlueShield of Tennessee is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
BlueCross BlueShield of Tennessee operates primarily in the Insurance industry.
BlueCross BlueShield of Tennessee employs approximately 4,877 people worldwide.
BlueCross BlueShield of Tennessee presently has no subsidiaries across any sectors.
BlueCross BlueShield of Tennessee’s official LinkedIn profile has approximately 40,691 followers.
BlueCross BlueShield of Tennessee is classified under the NAICS code 524, which corresponds to Insurance Carriers and Related Activities.
No, BlueCross BlueShield of Tennessee does not have a profile on Crunchbase.
Yes, BlueCross BlueShield of Tennessee maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/bcbst.
As of December 23, 2025, Rankiteo reports that BlueCross BlueShield of Tennessee has experienced 2 cybersecurity incidents.
BlueCross BlueShield of Tennessee has an estimated 15,102 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Data Leak and Breach.
Detection and Response: The company detects and responds to cybersecurity incidents through an containment measures with employers were instructed to delete the reports and certify their destruction, and communication strategy with people whose information was compromised were notified with a letter and offered a free identity protection service for up to two years..
Title: BlueCross BlueShield of Tennessee Data Breach
Description: Some member reports from BlueCross BlueShield of Tennessee were delivered to group benefit administrators due to a computer error. The report contained information on 2,100 members, including their names, birthdates, plan types, dates of coverage, and member identification numbers.
Date Detected: 2017-07-05
Type: Data Breach
Attack Vector: Computer Error
Vulnerability Exploited: Data Mishandling
Title: BlueCross BlueShield of Tennessee Data Breach
Description: Unauthorized access to email accounts of vendor EyeMed Vision Care, potentially affecting 1,340 individuals, including 3 Maine residents.
Date Detected: 2020-12-18
Date Publicly Disclosed: 2020-12-18
Type: Data Breach
Attack Vector: Unauthorized Access
Vulnerability Exploited: Email Accounts
Common Attack Types: The most common types of attacks the company has faced is Breach.
Identification of Attack Vectors: The company identifies the attack vectors used in incidents through Email Accounts.

Data Compromised: Names, Birthdates, Plan types, Dates of coverage, Member identification numbers

Data Compromised: Social security numbers
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Names, Birthdates, Plan Types, Dates Of Coverage, Member Identification Numbers, , Social Security Numbers and .

Entity Name: BlueCross BlueShield of Tennessee
Entity Type: Health Insurance
Industry: Healthcare
Location: Tennessee
Customers Affected: 2100

Entity Name: BlueCross BlueShield of Tennessee, Inc.
Entity Type: Health Insurance
Industry: Healthcare
Location: Tennessee
Customers Affected: 1340

Containment Measures: Employers were instructed to delete the reports and certify their destruction
Communication Strategy: People whose information was compromised were notified with a letter and offered a free identity protection service for up to two years

Type of Data Compromised: Names, Birthdates, Plan types, Dates of coverage, Member identification numbers
Number of Records Exposed: 2100
Sensitivity of Data: Medium
Personally Identifiable Information: NamesBirthdatesMember Identification Numbers

Type of Data Compromised: Social security numbers
Number of Records Exposed: 1340
Sensitivity of Data: High
Handling of PII Incidents: The company handles incidents involving personally identifiable information (PII) through by employers were instructed to delete the reports and certify their destruction.

Source: BlueCross BlueShield of Tennessee

Source: Maine Office of the Attorney General
Date Accessed: 2020-12-18
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: BlueCross BlueShield of Tennessee, and Source: Maine Office of the Attorney GeneralDate Accessed: 2020-12-18.
Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through People whose information was compromised were notified with a letter and offered a free identity protection service for up to two years.

Customer Advisories: Letter notification and offer of free identity protection service
Advisories Provided: The company provides the following advisories to stakeholders and customers following an incident: was Letter notification and offer of free identity protection service.

Entry Point: Email Accounts

Root Causes: Computer Error
Most Recent Incident Detected: The most recent incident detected was on 2017-07-05.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2020-12-18.
Most Significant Data Compromised: The most significant data compromised in an incident were Names, Birthdates, Plan Types, Dates of Coverage, Member Identification Numbers, , Social Security numbers and .
Containment Measures in Most Recent Incident: The containment measures taken in the most recent incident was Employers were instructed to delete the reports and certify their destruction.
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Member Identification Numbers, Names, Birthdates, Plan Types, Dates of Coverage and Social Security numbers.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 344.0.
Most Recent Source: The most recent source of information about an incident are BlueCross BlueShield of Tennessee and Maine Office of the Attorney General.
Most Recent Customer Advisory: The most recent customer advisory issued was an Letter notification and offer of free identity protection service.
Most Recent Entry Point: The most recent entry point used by an initial access broker was an Email Accounts.
.png)
A vulnerability has been found in SeaCMS up to 13.3. The affected element is an unknown function of the file js/player/dmplayer/dmku/class/mysqli.class.php. Such manipulation of the argument page/limit leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HappyDevs TempTool allows Stored XSS.This issue affects TempTool: from n/a through 1.3.1.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tormorten WP Microdata allows Stored XSS.This issue affects WP Microdata: from n/a through 1.0.
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in HappyDevs TempTool allows Retrieve Embedded Sensitive Data.This issue affects TempTool: from n/a through 1.3.1.
A vulnerability has been found in Tenda FH1201 1.2.0.14(408). Affected is the function sprintf of the file /goform/SetIpBind. Such manipulation of the argument page leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.