Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Health Care Service Corporation

Health Care Service Corporation Vendor Cyber Rating & Cyber Score

hcsc.com

Health Care Service Corporation serves nearly 23 million people across the United States through its portfolio of health benefit solutions. HCSC provides health coverage options for employers large and small, individuals and families, and Medicare and Medicaid plans. HCSC also offers related health care products and services such as pharmacy solutions, life and dental insurance, and health data technology. A Mutual Legal Reserve Company, HCSC is an independent licensee of the Blue Cross Blue Shield Association. For nearly a century, we have enabled and coordinated the access to quality care for millions of members. Our experience and industry knowledge establishes a solid foundation for our future—driving innovations that further expand


HCSC A.I CyberSecurity Scoring

HCSC
Company Information
Website:http://www.hcsc.com
Employees number:20,799
Number of followers:160,685
NAICS:62
Industry Type:Hospitals and Health Care
Homepage:hcsc.com
HCSC Risk Score (AI oriented)
Between 0 and 549
logo
HCSCHospitals and Health Care
Updated:
02/04/2026
427/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
HCSC Global Score (TPRM)
xxxx
logo
HCSCHospitals and Health Care
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

HCSC
HCSCCritical
Current Score
427C (CRITICAL)
01000
7 incidents
-67 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
443Before Incident
MAY 2026
438Before Incident
APRIL 2026
433Before Incident
MARCH 2026
423Before Incident
FEBRUARY 2026
414Before Incident
JANUARY 2026
413Before Incident
DECEMBER 2025
453Before Incident
NOVEMBER 2025
496Before Incident
OCTOBER 2025
511Before Incident
Breach
23 Oct 2025HCSC
Blue Cross Blue Shield of Montana (BCBSMT)

Blue Cross Blue Shield of Montana Data Breach

444After Incident
CRITICAL-67
HCS0692206102325
Blue Cross Blue Shield of Montana (BCBSMT), the largest health insurer in Montana, experienced a cybersecurity incident where an unauthorized user accessed membership data, compromising the personally identifiable information (PII) of 462,000 individuals. The exposed data included names, addresses, dates of birth, telephone/fax numbers, email addresses, medical record numbers, health plan beneficiary numbers, account numbers, billing information, and service dates. The breach exposed sensitive medical and financial details, raising concerns over identity theft, fraud, and misuse of health records. A national class-action law firm (Lynch Carpenter, LLP) is investigating potential claims for compensation, indicating significant legal and reputational repercussions. The incident highlights vulnerabilities in healthcare data security, with long-term risks for affected individuals, including financial fraud and privacy violations.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
telephone numbersfax numbersemail addressesmedical record numbershealth plan beneficiary numbersaccount numbersmedical/dental service detailsbilling informationnamesaddressesdates of birthservice datesBrand Reputation Impact: Potential reputational damage due to exposure of sensitive health and personal dataLegal Liabilities: Lynch Carpenter, LLP is investigating claims for potential compensation; class action lawsuit possibleIdentity Theft Risk: High (due to exposure of PII including names, addresses, dates of birth, and medical/financial details)Payment Information Risk: Moderate (account numbers and billing information exposed)
DATA BREACH
Personally Identifiable Information (PII)Protected Health Information (PHI)Number Of Records Exposed: 462,000Sensitivity Of Data: High (includes medical, financial, and personal identifiers)Data Exfiltration: Yes (records were obtained by unauthorized user)namesaddressesdates of birthtelephone numbersfax numbersemail addressesmedical record numbershealth plan beneficiary numbersaccount numbers
SEPTEMBER 2025
451Before Incident
AUGUST 2025
445Before Incident
JULY 2025
438Before Incident
MAY 2025
484Before Incident
Breach
01 May 2025HCSC
Blue Cross Blue Shield of Montana

Blue Cross Blue Shield of Montana Data Breach Investigation

479After Incident
CRITICAL-5
HCS1332313102325
Blue Cross Blue Shield of Montana (BCBSMT) is currently under investigation following a major data breach that exposed the personal and medical information of up to 462,000 customers in the state. The breach originated from a third-party vendor, Conduent, which experienced a cyber incident compromising BCBSMT member data. While BCBSMT confirmed its own systems remained unaffected, the incident has raised significant concerns over customer privacy and data security. The Montana State Auditor’s office is actively probing the breach, emphasizing the potential misuse of sensitive health and personal records, which could lead to identity theft, financial fraud, or targeted phishing attacks. The scale of the breach—affecting nearly half a million individuals—highlights systemic vulnerabilities in third-party vendor security protocols, particularly in the healthcare sector. Customers impacted may face long-term risks, including unauthorized access to medical histories, insurance fraud, or reputational harm to BCBSMT due to eroded trust. The breach underscores the critical need for robust cybersecurity measures, especially when handling highly sensitive health data, and may prompt regulatory scrutiny or legal repercussions for both BCBSMT and Conduent.
INCIDENT DETAILS -
TYPE
Data Breach (Third-Party Vendor Incident)
IMPACT
Personal InformationMedical InformationSystems Affected: None (Blue Cross systems were not impacted)Brand Reputation Impact: Potential (due to exposure of sensitive customer data)Identity Theft Risk: High (462,000 customers potentially affected)
DATA BREACH
Personal InformationMedical InformationNumber Of Records Exposed: 462,000Sensitivity Of Data: High (includes medical and personal details)Data Exfiltration: Likely (as data was 'impacted' by the incident)Personally Identifiable Information: Yes
FEBRUARY 2025
534Before Incident
Breach
01 Feb 2025HCSC
Montana Blue Cross-Blue Shield (Montana BCBS)

Montana Blue Cross-Blue Shield Vendor Data Breach

467After Incident
CRITICAL-67
HCS1202712111125
Montana Blue Cross-Blue Shield (Montana BCBS), the largest insurance carrier in Montana, experienced a severe data breach through one of its vendors. The breach lasted several months and was discovered in February but only reported to the Montana Commissioner of Securities and Insurance in October. It exposed the financial information and medical records of over 460,000 Montanans, including sensitive health and personal data. The breach posed significant risks of identity theft, financial fraud, and unauthorized access to private health records. In response, the Commissioner’s office deployed an AI-powered tool to assist affected residents in safeguarding their data, freezing credit, and monitoring for identity theft. A class-action lawsuit has also been filed by impacted residents. The breach involved a third-party vendor, highlighting vulnerabilities in supply chain security and the potential for large-scale exposure of highly sensitive personal and health data.
INCIDENT DETAILS -
TYPE
data breachthird-party vendor compromise
IMPACT
financial informationmedical recordsCustomer Complaints: class-action lawsuit filedBrand Reputation Impact: high (statewide breach affecting largest insurance carrier)Legal Liabilities: class-action lawsuitIdentity Theft Risk: high (financial and health data exposed)Payment Information Risk: high
DATA BREACH
financial informationmedical recordsNumber Of Records Exposed: 460,000+Sensitivity Of Data: high (financial + health data)
JANUARY 2025
597Before Incident
Breach
13 Jan 2025HCSC
Conduent and Montana Blue Cross-Blue Shield: Montana BCBS claims insurance commissioner targeting it because of data breach

Montana’s Largest Data Breach Sparks Legal Battle Between BCBS and State Regulators

531After Incident
CRITICAL-66
CONHCS1769138618
Montana’s Largest Data Breach Sparks Legal Battle Between BCBS and State Regulators Montana Blue Cross-Blue Shield (BCBS), the state’s largest health insurer, is locked in a dispute with the Montana Commissioner of Securities and Insurance (CSI) over its handling of a massive data breach the largest in state history. The breach, traced to third-party vendor Conduent, exposed the personal data of 462,356 individuals, including names, addresses, and Social Security numbers, affecting roughly one in three Montana residents. The conflict centers on the timeline of BCBS’s response. Conduent detected the breach on January 13, 2025, and notified BCBS four days later. However, BCBS claims it only discovered its own data was compromised in July, nearly six months later. The insurer did not alert the CSI until October 8 and began notifying customers on October 24, with some notifications still ongoing as recently as last week. State officials argue the delay violated Montana’s data breach notification laws, which require insurers to report incidents within a "reasonable" timeframe though the law does not define the term. Deputy Insurance Commissioner Erin Snyder testified that a months-long gap was unreasonable, while BCBS attorneys countered that the company fulfilled its obligations by eventually informing regulators and customers. During a contested hearing, BCBS accused the CSI of unfairly targeting it, noting that other companies affected by the same Conduent breach faced no disciplinary action. Snyder acknowledged the office was investigating the broader incident but had not pursued hearings against the other four entities, citing a far smaller impact (~200 people). The CSI has since implemented an AI-powered triage tool costing $10,000 to manage the surge in breach-related inquiries. However, regulators say they still lack a final report from BCBS detailing the full scope and cause of the breach, leaving critical questions unanswered. As the legal battle continues, the fallout highlights gaps in breach response protocols and regulatory oversight.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Personal data (names, addresses, Social Security numbers)Brand Reputation Impact: Significant (legal dispute, regulatory scrutiny)Legal Liabilities: Potential fines for delayed notificationIdentity Theft Risk: High (Social Security numbers exposed)
DATA BREACH
NamesAddressesSocial Security numbersNumber Of Records Exposed: 462,356Sensitivity Of Data: High (Personally Identifiable Information, Social Security numbers)Personally Identifiable Information: Yes
NOVEMBER 2024
656Before Incident
Breach
08 Nov 2024HCSC
Blue Cross Blue Shield of Montana (BCBSMT)

Blue Cross Blue Shield of Montana (BCBSMT) Third-Party Data Breach via Conduent

589After Incident
CRITICAL-67
HCS1192111102325
A third-party data breach involving Conduent, a business services provider for BCBSMT, exposed sensitive personal and medical data of up to 462,000 Montanans between November 8, 2024, and March 5, 2025. Compromised information includes names, addresses, birth dates, phone numbers, billing details, and medical records. While BCBSMT’s internal systems remained unaffected, the breach was described as having ‘far-reaching and jaw-dropping consequences’ by Montana’s State Auditor, James Brown. The exposed data was exfiltrated by a ‘threat actor’ but, per Conduent, has not been publicly leaked or sold on the dark web. BCBSMT claimed to offer credit monitoring to affected customers, though regulators reported delays in notifications. The incident prompted a full-scale state investigation, new cybersecurity initiatives, and a public awareness campaign to mitigate identity theft risks. Authorities emphasized accountability, transparency, and legal action against responsible parties.
INCIDENT DETAILS -
TYPE
data breachthird-party breachunauthorized access
IMPACT
namesaddressesbirth datesphone numbersbilling datamedical dataother sensitive informationConduent’s environment (limited portion)operations disruption (Conduent)regulatory investigationpublic awareness campaignsevereeroded consumer trustregulatory scrutinypotential finesregulatory actionslegal accountability demandshighstatewide public awareness campaign launched
DATA BREACH
personally identifiable information (PII)protected health information (PHI)billing dataNumber Of Records Exposed: 462,000Sensitivity Of Data: high (includes medical and financial data)
OCTOBER 2024
719Before Incident
Breach
01 Oct 2024HCSC
Blue Cross-Blue Shield of Montana

Blue Cross-Blue Shield of Montana Data Breach (2024-2025)

653After Incident
CRITICAL-66
HCS3702237102525
A massive data breach at Blue Cross-Blue Shield of Montana, the state’s largest health insurer, exposed the sensitive personal and healthcare data of 462,000 customers—nearly one-third of Montana’s population. The breach, caused by a third-party vendor (Conduent), lasted from October 2024 to January 2025 but was only disclosed in October 2025, nearly a year after discovery. Compromised data included birth dates, Social Security numbers, and health condition records, highly targeted by cybercriminals for identity theft, fraud, and dark web sales. Victims face risks of medical identity theft (average cost: $20,000 per incident), lost healthcare coverage, increased premiums, and long-term financial harm. The company failed to encrypt data, delete obsolete records, or notify affected individuals promptly, violating Montana’s breach disclosure laws. A class-action lawsuit alleges negligence, breach of contract, and violations of consumer protection laws, seeking damages, security reforms, and a decade of third-party monitoring. The breach has already led to spam, fraud calls, and identity theft cases, with victims unable to mitigate risks due to delayed alerts.
INCIDENT DETAILS -
TYPE
data breachthird-party vendor compromiseidentity theft risk
MOTIVATION
financial gain (data sale on dark web)identity theftfraud
IMPACT
Estimated Cost Per Victim: $20,000 (medical identity theft)Credit Monitoring Cost: $200/year per class member (minimum 5 years)Out Of Pocket Costs: common for victimsbirth datesSocial Security numbershealth condition datapersonally identifiable information (PII)third-party vendor systems (Conduent)customer databasesinvestigation by Montana Commissioner of Securities and Insuranceclass-action lawsuitcustomer notifications delayedspam callsfraud attemptsidentity theft reportsloss of trustnegative media coveragelegal scrutinyclass-action lawsuit (7 counts: negligence, breach of contract, Montana Consumer Protection Act violations, etc.)potential regulatory fineshigh (data sold on dark web for $40–$200 per record)complete dossiers assembled by cybercriminals
DATA BREACH
PII (birth dates, SSNs)health recordsprivate healthcare informationNumber Of Records Exposed: 462,000Sensitivity Of Data: high (medical + financial identity theft risk)
JUNE 2024
788Before Incident
Breach
16 Jun 2024HCSC
Blue Cross Blue Shield of Montana (BCBSMT)

Blue Cross Blue Shield of Montana (BCBSMT) Data Breach via Third-Party Vendor Conduent

715After Incident
CRITICAL-73
HCS1002310112225
Blue Cross Blue Shield of Montana (BCBSMT) suffered a large-scale data breach via a third-party vendor, Conduent, between late 2024 and early 2025. The incident compromised the personal and medical information of 462,000 Montanans—nearly one-third of the state’s population. Exposed data included names, addresses, birth dates, billing and medical records, phone numbers, and other sensitive details. The breach triggered an investigation by Montana’s State Auditor and Insurance Commissioner, James Brown, who criticized BCBSMT for delays in notification and transparency. The fallout led to regulatory scrutiny, potential enforcement actions, and a public awareness campaign urging affected residents to monitor financial and insurance statements for fraud. BCBSMT’s response remains under legal constraint, with the company declining to comment on pending litigation. The breach’s scale and sensitivity of leaked data—spanning health and financial records—pose severe risks of identity theft, medical fraud, and long-term reputational damage to both BCBSMT and the impacted individuals. Montana’s government deployed an AI assistant to manage the surge in consumer inquiries, highlighting the breach’s systemic impact on state-level cybersecurity and regulatory frameworks.
INCIDENT DETAILS -
TYPE
data breachthird-party vendor compromise
IMPACT
namesaddressesbirth datesbilling datamedical dataphone numbersother sensitive informationCustomer Complaints: surge in consumer questions (handled via AI assistant)Brand Reputation Impact: significant (described as 'deeply disturbing' with 'far-reaching consequences')Legal Liabilities: potential enforcement actions for untimely notification (investigation ongoing)Identity Theft Risk: high (residents urged to monitor Explanation of Benefits)
DATA BREACH
PII (Personally Identifiable Information)PHI (Protected Health Information)billing dataNumber Of Records Exposed: 462,000Sensitivity Of Data: high (includes medical and billing data)namesaddressesbirth datesphone numbers

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for HCSC ?
?
What was HCSC's A.I Rankiteo Cyber Score in May 2026 ?
?
What was HCSC's A.I Rankiteo Cyber Score in April 2026 ?
?
What was HCSC's A.I Rankiteo Cyber Score in March 2026 ?
?
What was HCSC's A.I Rankiteo Cyber Score in February 2026 ?
?
What was HCSC's A.I Rankiteo Cyber Score in January 2026 ?
?
What was HCSC's A.I Rankiteo Cyber Score in December 2025 ?
?
What was HCSC's A.I Rankiteo Cyber Score in November 2025 ?
?
What was HCSC's A.I Rankiteo Cyber Score in October 2025 ?
?
What was HCSC's A.I Rankiteo Cyber Score in September 2025 ?
?
What was HCSC's A.I Rankiteo Cyber Score in August 2025 ?
?
What was HCSC's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on HCSC's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with HCSC ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view HCSC's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Health Care Service Corporation Cyber Scoring History | Rankiteo