Company Details
humana
45,716
599,932
524
humana.com
474
HUM_3368866
Completed

Humana Company CyberSecurity Posture
humana.comHumana will never ask, nor require a candidate to provide money for work equipment and network access during the application process. If you become aware of any instances where you as a candidate are asked to provide information and do not believe it is a legitimate request from Humana or affiliate, please contact [email protected] to validate the request At Humana, our cultural foundation is aligned to helping members achieve their best health by delivering personalized, simplified, whole-person healthcare experiences. Recognizing healthcare needs continue to evolve for each person, for each family and for each community, Humana continuously creates innovative solutions and resources that help people live their healthiest lives on their terms –when and where they need it. Our employees are at the heart of making this happen and that’s why we are dedicated to building an organization of dynamic talent whose experience and passion center on putting the customer first.
Company Details
humana
45,716
599,932
524
humana.com
474
HUM_3368866
Completed
Between 650 and 699

Humana Global Score (TPRM)XXXX

Description: The Maine Office of the Attorney General reported on October 24, 2023, that Humana Inc experienced a data breach on August 9, 2023, due to unauthorized access to their document processing system, affecting 2,844 individuals in total, including 16 residents. The breached information included names, Humana identification numbers, provider names, and service dates.
Description: The California Office of the Attorney General reported a data breach involving Humana Inc on January 3, 2019. The breach occurred between May 30 and September 13, 2018, due to unauthorized access to employee system credentials at Bankers Life, potentially affecting personal information of individuals who applied for Humana health insurance policies.
Description: The California Office of the Attorney General reported that Humana Inc experienced a data breach involving the disclosure of personal information by an employee of a subcontractor on March 8, 2021. The breach date occurred between October 12, 2020, and December 16, 2020, potentially affecting member details, including names and birthdates.
Description: Humana suffered a data breach incident after Choice Health, one of the companies it uses to help sell its products, experienced a cyberattack. The breach exposed some customers’ first and last names, Social Security numbers, Medicare beneficiary identification numbers, dates of birth, addresses, contact information and health insurance information. Humana sent out data breach letters to all affected parties, informing them of the incident and the ways to protect themselves from fraud.
Description: Humana, Inc. experienced a data breach on **May 7, 2022**, due to unauthorized access to its systems. The incident exposed sensitive personal information of **639 Washington State residents**, including **names, Social Security numbers, and health insurance details**. The breach was formally reported to the **Washington State Office of the Attorney General** on **September 8, 2022**, indicating a delayed discovery or disclosure. The compromised data poses significant risks, such as identity theft, financial fraud, and potential misuse of health-related information. While the exact method of unauthorized access was not specified, the exposure of **Social Security numbers**—a high-value target for cybercriminals—heightens the severity. The breach underscores vulnerabilities in Humana’s data protection measures, raising concerns about compliance with regulatory standards like **HIPAA** and the potential for long-term reputational damage.
Description: On May 30, 2023, Humana, Inc. (via its subsidiary Welltok, Inc.) fell victim to a **malware-based cyberattack**, exposing sensitive data of **33,193 Washington State residents**. The breach compromised **personal identifiers**—including **full names, dates of birth, health insurance policy/ID numbers**, and **medical information**. The incident highlights a severe **data security failure**, where attackers exploited vulnerabilities to access protected health information (PHI). Such exposure poses risks of **identity theft, medical fraud, and targeted phishing**, as the leaked data could enable malicious actors to impersonate victims for financial or healthcare-related scams. The breach also undermines trust in Humana’s ability to safeguard patient confidentiality, potentially leading to **regulatory penalties** under laws like HIPAA (Health Insurance Portability and Accountability Act). While the attack did not involve ransomware, the **scale and sensitivity of the leaked data**—particularly medical records—elevate its severity. The compromised information could have long-term repercussions for affected individuals, including **discrimination risks** (e.g., based on pre-existing conditions) or **unauthorized access to healthcare services**. Humana’s response, including notification and mitigation measures, remains critical to limiting further harm.
Description: The Maine Office of the Attorney General reported on September 28, 2021, that Humana experienced a data breach involving a ransomware attack on PracticeMax. The breach occurred from April 17, 2021, to May 5, 2021, and potentially affected 4,424 individuals, involving unauthorized access to Protected Health Information (PHI). PracticeMax has offered credit monitoring services for a minimum of 12 months to affected individuals.


No incidents recorded for Humana in 2025.
No incidents recorded for Humana in 2025.
No incidents recorded for Humana in 2025.
Humana cyber incidents detection timeline including parent company and subsidiaries

Humana will never ask, nor require a candidate to provide money for work equipment and network access during the application process. If you become aware of any instances where you as a candidate are asked to provide information and do not believe it is a legitimate request from Humana or affiliate, please contact [email protected] to validate the request At Humana, our cultural foundation is aligned to helping members achieve their best health by delivering personalized, simplified, whole-person healthcare experiences. Recognizing healthcare needs continue to evolve for each person, for each family and for each community, Humana continuously creates innovative solutions and resources that help people live their healthiest lives on their terms –when and where they need it. Our employees are at the heart of making this happen and that’s why we are dedicated to building an organization of dynamic talent whose experience and passion center on putting the customer first.


SURA es una compañía que integra en diferentes empresas soluciones en seguros y seguridad social. Su marca se presenta a los clientes como Seguros SURA, ARL SURA y EPS SURA. Existen otras marcas y empresas, especialmente de prestación de servicios, que hacen parte de la Compañía. Nuestra experienc

For more than 90 years, American Family Insurance has built its reputation on sound principles. We strive to provide you industry-leading service, exceptional claims experience and products that build long-term relationships. This is accomplished by treating policyholders fairly in a helpful and car

Axis Max Life Insurance Limited (earlier known as Max Life Insurance Company Limited) is a Joint Venture between Max Financial Services Limited and Axis Bank Limited. Max Financial Services Ltd. is a part of the Max Group, an Indian multi-business corporation. Axis Max Life Insurance Limited has an

The Life Insurance Corporation of India (LIC) is a state-owned Life Insurance Company of India. Founded in 1956, it operates as a Government-Owned Corporation, headquartered in Mumbai, Maharashtra, and is a key player in the life insurance sector in India. LIC offers a wide range of insurance produ
As one of the largest global insurers, our purpose is to act for human progress by protecting what matters. Protection has always been at the core of our business, helping individuals, businesses and societies to thrive. And AXA has always been a leader, an innovator, an entrepreneurial company, fo

« Etre là pour les autres, j'ai décidé d'en faire mon métier. » Portée par nos 32 000 collaborateurs, notre campagne de communication employeur souligne ce qui nous rassemble et nous rend fiers au quotidien : notre métier, le point de départ de belles histoires, humaines avant tout. Cette campagne
The companies comprising the Farmers Insurance Group of Companies® currently make up one of the country's largest insurers of vehicles, homes and small businesses, and provide a wide range of other specialty insurance and financial services products. In business since 1928, today at Farmers® we pr

Allianz Partners is a world leader in B2B2C insurance and assistance, offering global solutions that span international health and life, travel insurance, automotive and assistance. Customer driven, our innovative experts are redefining insurance services by delivering future-ready, high-tech high-t
At Allstate, we're advocates for peace of mind and a good life. And that comes through in everything we do. From building innovative teams that truly understand our customers' needs, to challenging each other to develop our careers in a meaningful way, and finally to the incredible results we're a
.png)
By launching a shared interoperability framework, Providence and Humana are addressing a long-standing challenge in health care: the...
Humana reported $195 million in third quarter profits as the health insurer's medical cost trends were in line with forecasts for the...
CHONGQING, CHINA - JULY 28: In this photo illustration, a smartphone displays the logo of Humana Inc. (NYSE: HUM), a leading American health...
Boards seeking consistent returns and strategic innovation might not need to look outside the organization for their next growth driver.
Humana's CenterWell will begin filling and shipping orders for the GLP-1 weight loss drug Wegovy that are prescribed through Hims & Hers...
Humana (NYSE:HUM) stock looks very attractive - making it a very good pick to buy at its current price of around $290.
Data breach at Humana Inc. affects 8553, exposing personal and health insurance details. Monitor accounts and stay alert.
Humana Inc., a leading health and well-being company, has released its 2024 10-K report, detailing its financial and operational performance...
Humana will be expanding its CenterWell and Conviva brand primary care operations into 11 states – including four new markets - where the company has medical...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Humana is https://careers.humana.com/.
According to Rankiteo, Humana’s AI-generated cybersecurity score is 661, reflecting their Weak security posture.
According to Rankiteo, Humana currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Humana is not certified under SOC 2 Type 1.
According to Rankiteo, Humana does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Humana is not listed as GDPR compliant.
According to Rankiteo, Humana does not currently maintain PCI DSS compliance.
According to Rankiteo, Humana is not compliant with HIPAA regulations.
According to Rankiteo,Humana is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Humana operates primarily in the Insurance industry.
Humana employs approximately 45,716 people worldwide.
Humana presently has no subsidiaries across any sectors.
Humana’s official LinkedIn profile has approximately 599,932 followers.
Humana is classified under the NAICS code 524, which corresponds to Insurance Carriers and Related Activities.
Yes, Humana has an official profile on Crunchbase, which can be accessed here: https://www.crunchbase.com/organization/humana.
Yes, Humana maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/humana.
As of December 14, 2025, Rankiteo reports that Humana has experienced 7 cybersecurity incidents.
Humana has an estimated 15,044 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Cyber Attack, Ransomware and Breach.
Detection and Response: The company detects and responds to cybersecurity incidents through an communication strategy with humana sent out data breach letters to all affected parties, informing them of the incident and the ways to protect themselves from fraud., and communication strategy with public disclosure via washington state office of the attorney general..
Title: Humana Data Breach Incident
Description: Humana suffered a data breach incident after Choice Health, one of the companies it uses to help sell its products, experienced a cyberattack. The breach exposed some customers’ first and last names, Social Security numbers, Medicare beneficiary identification numbers, dates of birth, addresses, contact information and health insurance information. Humana sent out data breach letters to all affected parties, informing them of the incident and the ways to protect themselves from fraud.
Type: Data Breach
Title: Humana Inc Data Breach
Description: The California Office of the Attorney General reported a data breach involving Humana Inc on January 3, 2019. The breach occurred between May 30 and September 13, 2018, due to unauthorized access to employee system credentials at Bankers Life, potentially affecting personal information of individuals who applied for Humana health insurance policies.
Date Detected: 2019-01-03
Date Publicly Disclosed: 2019-01-03
Type: Data Breach
Attack Vector: Unauthorized Access
Vulnerability Exploited: Employee System Credentials
Title: Humana Inc Data Breach
Description: Unauthorized access to Humana Inc's document processing system resulting in a data breach affecting 2,844 individuals.
Date Detected: 2023-08-09
Date Publicly Disclosed: 2023-10-24
Type: Data Breach
Attack Vector: Unauthorized Access
Title: Humana Inc Data Breach
Description: The California Office of the Attorney General reported that Humana Inc experienced a data breach involving the disclosure of personal information by an employee of a subcontractor on March 8, 2021. The breach date occurred between October 12, 2020, and December 16, 2020, potentially affecting member details, including names and birthdates.
Date Detected: 2021-03-08
Type: Data Breach
Attack Vector: Human Error
Threat Actor: Employee of a subcontractor
Title: Humana Data Breach via PracticeMax Ransomware Attack
Description: The Maine Office of the Attorney General reported on September 28, 2021, that Humana experienced a data breach involving a ransomware attack on PracticeMax. The breach occurred from April 17, 2021, to May 5, 2021, and potentially affected 4,424 individuals, involving unauthorized access to Protected Health Information (PHI). PracticeMax has offered credit monitoring services for a minimum of 12 months to affected individuals.
Date Detected: 2021-05-05
Date Publicly Disclosed: 2021-09-28
Type: Data Breach, Ransomware
Attack Vector: Ransomware
Title: Humana (Welltok, Inc.) Cyberattack Involving Malware
Description: The Washington State Office of the Attorney General reported that Humana, Inc. (Welltok, Inc.) experienced a cyberattack involving malware on May 30, 2023, affecting 33,193 residents. The breach potentially compromised names, full dates of birth, health insurance policy or ID numbers, and medical information.
Date Detected: 2023-05-30
Type: Cyberattack (Malware)
Title: Humana, Inc. Data Breach (2022)
Description: The Washington State Office of the Attorney General reported that Humana, Inc. experienced a data breach due to unauthorized access on May 7, 2022. Approximately 639 residents were affected, and the compromised data included personal information such as names, Social Security numbers, and health insurance information.
Date Detected: 2022-05-07
Date Publicly Disclosed: 2022-09-08
Type: Data Breach
Common Attack Types: The most common types of attacks the company has faced is Breach.

Data Compromised: First and last names, Social security numbers, Medicare beneficiary identification numbers, Dates of birth, Addresses, Contact information, Health insurance information

Data Compromised: Personal Information

Data Compromised: Names, Humana identification numbers, Provider names, Service dates
Systems Affected: document processing system

Data Compromised: Names, Birthdates

Data Compromised: Protected Health Information (PHI)

Data Compromised: Names, Full dates of birth, Health insurance policy or id numbers, Medical information
Identity Theft Risk: High (PII and medical data exposed)

Data Compromised: Names, Social security numbers, Health insurance information
Identity Theft Risk: High (PII exposed)
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Pii, Health Information, , Personal Information, Names, Humana Identification Numbers, Provider Names, Service Dates, , Personal Information, , Protected Health Information (PHI), Personally Identifiable Information (Pii), Protected Health Information (Phi), , Personal Identifiable Information (Pii), Protected Health Information (Phi) and .

Entity Name: Humana
Entity Type: Health Insurance Company
Industry: Healthcare

Entity Name: Humana Inc
Entity Type: Health Insurance Company
Industry: Healthcare

Entity Name: Humana Inc
Entity Type: Health Insurance Company
Industry: Healthcare
Customers Affected: 2844

Entity Name: Humana Inc
Entity Type: Healthcare
Industry: Healthcare

Entity Name: Humana
Entity Type: Healthcare
Industry: Healthcare
Customers Affected: 4424

Entity Name: Humana, Inc. (Welltok, Inc.)
Entity Type: Healthcare
Industry: Health Insurance
Location: Washington State (affecting 33,193 residents)
Customers Affected: 33,193

Entity Name: Humana, Inc.
Entity Type: Health Insurance Provider
Industry: Healthcare
Location: United States (Washington State residents affected)
Customers Affected: 639

Communication Strategy: Humana sent out data breach letters to all affected parties, informing them of the incident and the ways to protect themselves from fraud.

Communication Strategy: Public disclosure via Washington State Office of the Attorney General

Type of Data Compromised: Pii, Health information
Sensitivity of Data: High
Personally Identifiable Information: first and last namesSocial Security numbersMedicare beneficiary identification numbersdates of birthaddressescontact information

Type of Data Compromised: Personal Information

Type of Data Compromised: Names, Humana identification numbers, Provider names, Service dates
Number of Records Exposed: 2844
Personally Identifiable Information: namesHumana identification numbers

Type of Data Compromised: Personal information
Personally Identifiable Information: NamesBirthdates

Type of Data Compromised: Protected Health Information (PHI)
Number of Records Exposed: 4424
Sensitivity of Data: High

Type of Data Compromised: Personally identifiable information (pii), Protected health information (phi)
Number of Records Exposed: 33,193
Sensitivity of Data: High
Personally Identifiable Information: NamesFull dates of birthHealth insurance policy or ID numbers

Type of Data Compromised: Personal identifiable information (pii), Protected health information (phi)
Number of Records Exposed: 639
Sensitivity of Data: High
Data Exfiltration: Yes
Personally Identifiable Information: namesSocial Security numbers

Regulatory Notifications: Washington State Office of the Attorney General

Regulatory Notifications: Washington State Office of the Attorney General

Source: California Office of the Attorney General
Date Accessed: 2019-01-03

Source: Maine Office of the Attorney General
Date Accessed: 2023-10-24

Source: California Office of the Attorney General

Source: Maine Office of the Attorney General
Date Accessed: 2021-09-28

Source: Washington State Office of the Attorney General

Source: Washington State Office of the Attorney General
Date Accessed: 2022-09-08
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: California Office of the Attorney GeneralDate Accessed: 2019-01-03, and Source: Maine Office of the Attorney GeneralDate Accessed: 2023-10-24, and Source: California Office of the Attorney General, and Source: Maine Office of the Attorney GeneralDate Accessed: 2021-09-28, and Source: Washington State Office of the Attorney General, and Source: Washington State Office of the Attorney GeneralDate Accessed: 2022-09-08.
Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Humana sent out data breach letters to all affected parties, informing them of the incident and the ways to protect themselves from fraud. and Public disclosure via Washington State Office of the Attorney General.
Last Attacking Group: The attacking group in the last incident was an Employee of a subcontractor.
Most Recent Incident Detected: The most recent incident detected was on 2019-01-03.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2022-09-08.
Most Significant Data Compromised: The most significant data compromised in an incident were first and last names, Social Security numbers, Medicare beneficiary identification numbers, dates of birth, addresses, contact information, health insurance information, , Personal Information, names, Humana identification numbers, provider names, service dates, , Names, Birthdates, , Protected Health Information (PHI), Names, Full dates of birth, Health insurance policy or ID numbers, Medical information, , names, Social Security numbers, health insurance information and .
Most Significant System Affected: The most significant system affected in an incident was document processing system.
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were first and last names, Birthdates, health insurance information, names, Humana identification numbers, Names, dates of birth, Personal Information, Social Security numbers, addresses, contact information, service dates, Health insurance policy or ID numbers, Medicare beneficiary identification numbers, Protected Health Information (PHI), Full dates of birth, Medical information and provider names.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 34.6K.
Most Recent Source: The most recent source of information about an incident are Maine Office of the Attorney General, Washington State Office of the Attorney General and California Office of the Attorney General.
.png)
A weakness has been identified in itsourcecode Online Pet Shop Management System 1.0. This vulnerability affects unknown code of the file /pet1/addcnp.php. This manipulation of the argument cnpname causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited.
A security flaw has been discovered in Tenda AX9 22.03.01.46. This affects the function image_check of the component httpd. The manipulation results in use of weak hash. It is possible to launch the attack remotely. A high complexity level is associated with this attack. It is indicated that the exploitability is difficult. The exploit has been released to the public and may be exploited.
A weakness has been identified in code-projects Student File Management System 1.0. This issue affects some unknown processing of the file /admin/update_student.php. This manipulation of the argument stud_id causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.
A security flaw has been discovered in code-projects Student File Management System 1.0. This vulnerability affects unknown code of the file /admin/save_user.php. The manipulation of the argument firstname results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be exploited.
A vulnerability was identified in code-projects Student File Management System 1.0. This affects an unknown part of the file /admin/update_user.php. The manipulation of the argument user_id leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.