Company Details
highmark-health
15,287
68,597
62
highmarkhealth.org
0
HIG_1346406
In-progress

Highmark Health Company CyberSecurity Posture
highmarkhealth.orgA national blended health organization, Highmark Health and our leading businesses support millions of customers with products, services and solutions closely aligned to our mission of creating remarkable health experiences, freeing people to be their best. Headquartered in Pittsburgh, we're regionally focused in Pennsylvania, Delaware, West Virginia and New York, with customers in all 50 states and the District of Columbia. We passionately serve individual consumers and fellow businesses alike. Our companies cover a diversified spectrum of essential health-related needs, including health insurance, health care delivery, population health management, dental solutions, reinsurance solutions, and innovative technology solutions. Our financial position reflects strength and stability, with our year-end 2024 consolidated revenues totaling $29.4 billion. We’re also proud to carry forth an important legacy of compassionate care and philanthropy that began more than 170 years ago. This tradition of giving back, reinvesting and ensuring that our communities remain strong and healthy is deeply embedded in our culture, informing our decisions every day.
Company Details
highmark-health
15,287
68,597
62
highmarkhealth.org
0
HIG_1346406
In-progress
Between 700 and 749

Highmark Health Global Score (TPRM)XXXX

Description: The Maine Office of the Attorney General reported a data breach involving Highmark on February 3, 2023. The breach occurred between December 13, 2022, and December 15, 2022, due to an external hacking incident, potentially affecting 300,000 individuals, including 2,774 Maine residents. The compromised information included names and social security numbers.
Description: Highmark Health, based in Pittsburgh confirmed a security incident in its computer network that resulted in a data security breach. The breach exposed the sensitive information of as many as 67,147 individuals. Highmark Health investigated the incident and notified the impacted customers to be alerted of any fraudulent activity.
Description: The Washington State Office of the Attorney General reported a data breach involving Highmark Health on February 6, 2023. The breach occurred between December 13 and December 15, 2022, due to a phishing cyberattack, potentially affecting the personal and protected health information of 1,980 residents.
Description: A former employee of Highmark, according to the district attorney's office, allegedly broke into the accounts of multiple customers, including a school system, and took $1,000. Zakayah Scott, who performed remote work for Highmark Health from South Carolina, was charged by the Allegheny County District Attorney's office. The authorities claimed that Scott had access to the birthdays, residences, and phone numbers of his clients. They claimed she changed the victims' health savings account passwords over the phone, logged in, and then transferred and took money while posing as one of the victims.


No incidents recorded for Highmark Health in 2025.
No incidents recorded for Highmark Health in 2025.
No incidents recorded for Highmark Health in 2025.
Highmark Health cyber incidents detection timeline including parent company and subsidiaries

A national blended health organization, Highmark Health and our leading businesses support millions of customers with products, services and solutions closely aligned to our mission of creating remarkable health experiences, freeing people to be their best. Headquartered in Pittsburgh, we're regionally focused in Pennsylvania, Delaware, West Virginia and New York, with customers in all 50 states and the District of Columbia. We passionately serve individual consumers and fellow businesses alike. Our companies cover a diversified spectrum of essential health-related needs, including health insurance, health care delivery, population health management, dental solutions, reinsurance solutions, and innovative technology solutions. Our financial position reflects strength and stability, with our year-end 2024 consolidated revenues totaling $29.4 billion. We’re also proud to carry forth an important legacy of compassionate care and philanthropy that began more than 170 years ago. This tradition of giving back, reinvesting and ensuring that our communities remain strong and healthy is deeply embedded in our culture, informing our decisions every day.

Founded in 1866, University Hospitals serves the needs of patients through an integrated network of 23 hospitals (including 5 joint ventures), more than 50 health centers and outpatient facilities, and over 200 physician offices in 16 counties throughout northern Ohio. The system’s flagship quaterna

NorthShore University HealthSystem, Swedish Hospital, Northwest Community Healthcare and Edward-Elmhurst Health are now united under one name: Endeavor Health. Together, we’re driven by our mission to help everyone in our communities be their best and our commitment to setting a new standard for he

Express Scripts by Evernorth provides pharmacy benefits services with a clear mission: To simplify complexities and provide holistic, condition-focused care and clinically superior pharmacy benefit solutions for our clients and the people they serve. Guided by our core values of service, patient ca

When it comes to your health, everything matters. That’s why UnitedHealthcare is helping people live healthier lives and making the health system work better for everyone. Our health plans are there for you in moments big and small, delivering a simple experience, affordable coverage, and supportive

BayCare is a leading not-for-profit academic health care system that connects individuals and families to a wide range of services at 16 hospitals, including a children’s hospital, and hundreds of other convenient locations throughout the Tampa Bay and central Florida regions. The system is West Cen

The University of Maryland Medical System (UMMS) was created in 1984 when the state-owned University Hospital became a private, nonprofit organization. It has evolved into a multi-hospital system with academic, community and specialty service missions reaching every part of the state and beyond. UM

Nationwide Children’s is one of America's largest pediatric hospitals, an international leader in research and is ranked in all 10 specialties on U.S. News & World Report’s 2025-26 “America’s Best Children’s Hospitals” list. Our staff, comprised of 1,600 medical professionals and over 16,000 employe

Com cerca de 80 anos de experiência, a Hapvida é hoje a maior empresa de saúde integrada da América Latina. A companhia, que possui mais de 69 mil colaboradores, atende quase 16 milhões de beneficiários de saúde e odontologia espalhados pelas cinco regiões do Brasil. Todo o aparato foi construído a
A Dasa é a maior rede de saúde integrada do Brasil. Faz parte da vida de mais de 20 milhões de pessoas por ano, com alta tecnologia, experiência intuitiva e atitude à frente do tempo. Com mais de 50 mil colaboradores e 250 mil médicos parceiros, existe para ser a saúde que as pessoas desejam e que
.png)
Highmark Health announced today that its Board of Directors has appointed Karen Hanlon president of Highmark Health effective immediately.
Hanlon will retain her role as chief operating officer, which she has held since 2018.
Each year, the healthcare industry organizes a full slate of events that help executives stay on top of the latest trends and innovations in...
A lawsuit has been filed against Alphabet-owned Verily by a former employee who alleges that the personally identifiable health information...
Highmark Health and clinical documentation vendor Abridge are developing a tool that uses generative artificial intelligence to approve...
This month, we're highlighting 48 CIOs, CTOs, and CISOs taking on leadership roles in industries from healthcare to finance to technology.
Here are the five key takeaways from last week's AHIP conference, including a push to reform prior authorization.
Highmark Health recorded $13 million in net income during the first quarter, down from a $194 million a year before.
enGen, a wholly owned healthtech subsidiary of Highmark Health focused on providing integrated end-to-end technology solutions to health plans and their...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Highmark Health is http://www.highmarkhealth.org.
According to Rankiteo, Highmark Health’s AI-generated cybersecurity score is 705, reflecting their Moderate security posture.
According to Rankiteo, Highmark Health currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Highmark Health is not certified under SOC 2 Type 1.
According to Rankiteo, Highmark Health does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Highmark Health is not listed as GDPR compliant.
According to Rankiteo, Highmark Health does not currently maintain PCI DSS compliance.
According to Rankiteo, Highmark Health is not compliant with HIPAA regulations.
According to Rankiteo,Highmark Health is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Highmark Health operates primarily in the Hospitals and Health Care industry.
Highmark Health employs approximately 15,287 people worldwide.
Highmark Health presently has no subsidiaries across any sectors.
Highmark Health’s official LinkedIn profile has approximately 68,597 followers.
Highmark Health is classified under the NAICS code 62, which corresponds to Health Care and Social Assistance.
Yes, Highmark Health has an official profile on Crunchbase, which can be accessed here: https://www.crunchbase.com/organization/highmark-health.
Yes, Highmark Health maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/highmark-health.
As of November 27, 2025, Rankiteo reports that Highmark Health has experienced 4 cybersecurity incidents.
Highmark Health has an estimated 29,991 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Data Leak, Breach and Cyber Attack.
Total Financial Loss: The total financial loss from these incidents is estimated to be $1 thousand.
Detection and Response: The company detects and responds to cybersecurity incidents through an communication strategy with notified impacted customers to be alerted of any fraudulent activity., and law enforcement notified with yes..
Title: Highmark Health Data Breach
Description: Highmark Health, based in Pittsburgh confirmed a security incident in its computer network that resulted in a data security breach.
Type: Data Breach
Title: Former Highmark Employee Allegedly Breaches Customer Accounts
Description: A former employee of Highmark allegedly broke into the accounts of multiple customers, including a school system, and stole $1,000.
Type: Data Breach
Attack Vector: Account Takeover
Vulnerability Exploited: Unauthorized Access
Threat Actor: Zakayah Scott
Motivation: Financial Gain
Title: Highmark Health Data Breach
Description: The Washington State Office of the Attorney General reported a data breach involving Highmark Health on February 6, 2023. The breach occurred between December 13 and December 15, 2022, due to a phishing cyberattack, potentially affecting the personal and protected health information of 1,980 residents.
Date Detected: 2023-02-06
Date Publicly Disclosed: 2023-02-06
Type: Data Breach
Attack Vector: Phishing
Title: Highmark Data Breach
Description: The Maine Office of the Attorney General reported a data breach involving Highmark on February 3, 2023. The breach occurred between December 13, 2022, and December 15, 2022, due to an external hacking incident, potentially affecting 300,000 individuals, including 2,774 Maine residents. The compromised information included names and social security numbers.
Date Detected: 2023-02-03
Date Publicly Disclosed: 2023-02-03
Type: Data Breach
Attack Vector: External Hacking
Common Attack Types: The most common types of attacks the company has faced is Breach.
Identification of Attack Vectors: The company identifies the attack vectors used in incidents through Remote Access.

Data Compromised: Sensitive information

Financial Loss: $1,000
Data Compromised: Birthdays, Residences, Phone numbers

Data Compromised: Personal information, Protected health information

Data Compromised: Names, Social security numbers
Average Financial Loss: The average financial loss per incident is $250.00.
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Sensitive Information, Birthdays, Residences, Phone Numbers, , Personal Information, Protected Health Information, , Names, Social Security Numbers and .

Entity Name: Highmark Health
Entity Type: Healthcare Organization
Industry: Healthcare
Location: Pittsburgh
Customers Affected: 67147

Entity Name: Highmark Health
Entity Type: Health Insurance Company
Industry: Healthcare
Location: Allegheny County
Customers Affected: Multiple, including a school system

Entity Name: Highmark Health
Entity Type: Healthcare
Industry: Healthcare
Location: Washington State
Customers Affected: 1980

Entity Name: Highmark
Entity Type: Health Insurance Company
Industry: Healthcare
Customers Affected: 300000

Communication Strategy: Notified impacted customers to be alerted of any fraudulent activity.

Law Enforcement Notified: Yes

Type of Data Compromised: Sensitive Information
Number of Records Exposed: 67147

Type of Data Compromised: Birthdays, Residences, Phone numbers
Sensitivity of Data: Medium
Personally Identifiable Information: Yes

Type of Data Compromised: Personal information, Protected health information
Number of Records Exposed: 1980

Type of Data Compromised: Names, Social security numbers
Number of Records Exposed: 300000
Sensitivity of Data: High

Source: Washington State Office of the Attorney General
Date Accessed: 2023-02-06

Source: Maine Office of the Attorney General
Date Accessed: 2023-02-03
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Washington State Office of the Attorney GeneralDate Accessed: 2023-02-06, and Source: Maine Office of the Attorney GeneralDate Accessed: 2023-02-03.
Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Notified impacted customers to be alerted of any fraudulent activity..

Customer Advisories: Notified impacted customers to be alerted of any fraudulent activity.
Advisories Provided: The company provides the following advisories to stakeholders and customers following an incident: was Notified impacted customers to be alerted of any fraudulent activity..

Entry Point: Remote Access
Last Attacking Group: The attacking group in the last incident was an Zakayah Scott.
Most Recent Incident Detected: The most recent incident detected was on 2023-02-06.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2023-02-03.
Highest Financial Loss: The highest financial loss from an incident was $1,000.
Most Significant Data Compromised: The most significant data compromised in an incident were Sensitive Information, , birthdays, residences, phone numbers, , Personal Information, Protected Health Information, , Names, Social Security Numbers and .
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Social Security Numbers, Names, phone numbers, Protected Health Information, birthdays, Sensitive Information, residences and Personal Information.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 1.2K.
Most Recent Source: The most recent source of information about an incident are Maine Office of the Attorney General and Washington State Office of the Attorney General.
Most Recent Customer Advisory: The most recent customer advisory issued was an Notified impacted customers to be alerted of any fraudulent activity.
Most Recent Entry Point: The most recent entry point used by an initial access broker was an Remote Access.
.png)
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF token leakage via protocol-relative URLs in angular HTTP clients. The vulnerability is a Credential Leak by App Logic that leads to the unauthorized disclosure of the Cross-Site Request Forgery (XSRF) token to an attacker-controlled domain. Angular's HttpClient has a built-in XSRF protection mechanism that works by checking if a request URL starts with a protocol (http:// or https://) to determine if it is cross-origin. If the URL starts with protocol-relative URL (//), it is incorrectly treated as a same-origin request, and the XSRF token is automatically added to the X-XSRF-TOKEN header. This issue has been patched in versions 19.2.16, 20.3.14, and 21.0.1. A workaround for this issue involves avoiding using protocol-relative URLs (URLs starting with //) in HttpClient requests. All backend communication URLs should be hardcoded as relative paths (starting with a single /) or fully qualified, trusted absolute URLs.
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft deep ASN.1 structures that trigger unbounded recursive parsing. This leads to a Denial-of-Service (DoS) via stack exhaustion when parsing untrusted DER inputs. This issue has been patched in version 1.3.2.
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overflow vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft ASN.1 structures containing OIDs with oversized arcs. These arcs may be decoded as smaller, trusted OIDs due to 32-bit bitwise truncation, enabling the bypass of downstream OID-based security decisions. This issue has been patched in version 1.3.2.
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, working with large buffers in Lua scripts can lead to a stack overflow. Users of Lua rules and output scripts may be affected when working with large buffers. This includes a rule passing a large buffer to a Lua script. This issue has been patched in versions 7.0.13 and 8.0.2. A workaround for this issue involves disabling Lua rules and output scripts, or making sure limits, such as stream.depth.reassembly and HTTP response body limits (response-body-limit), are set to less than half the stack size.
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, a NULL dereference can occur when the entropy keyword is used in conjunction with base64_data. This issue has been patched in version 8.0.2. A workaround involves disabling rules that use entropy in conjunction with base64_data.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.