Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Humana

Humana Vendor Cyber Rating & Cyber Score

humana.com

Humana will never ask, nor require a candidate to provide money for work equipment and network access during the application process. If you become aware of any instances where you as a candidate are asked to provide information and do not believe it is a legitimate request from Humana or affiliate, please contact [email protected] to validate the request At Humana, our cultural foundation is aligned to helping members achieve their best health by delivering personalized, simplified, whole-person healthcare experiences. Recognizing healthcare needs continue to evolve for each person, for each family and for each community, Humana continuously creates innovative solutions and resources that help people live their healthiest lives on


Humana A.I CyberSecurity Scoring

Humana
Company Information
Website:https://careers.humana.com/
Employees number:46,895
Number of followers:658,912
NAICS:524
Industry Type:Insurance
Homepage:humana.com
Humana Risk Score (AI oriented)
Between 550 and 599
logo
HumanaInsurance
Updated:
01/04/2026
556/1000
Very Poor
Ca
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Humana Global Score (TPRM)
xxxx
logo
HumanaInsurance
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Humana
HumanaVery Poor
Current Score
556Ca (VERY POOR)
01000
8 incidents
-121 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
612Before Incident
MAY 2026
581Before Incident
APRIL 2026
565Before Incident
MARCH 2026
556Before Incident
FEBRUARY 2026
551Before Incident
JANUARY 2026
546Before Incident
DECEMBER 2025
534Before Incident
NOVEMBER 2025
532Before Incident
OCTOBER 2025
526Before Incident
SEPTEMBER 2025
520Before Incident
AUGUST 2025
628Before Incident
Ransomware
01 Aug 2025Humana
Centerwell, Humana, Oracle and Catalyst RCM: Humana warns patients of data breach that leaked SSNs, medical info

Humana and Centerwell Hit by Clop Ransomware Attack

507After Incident
CRITICAL-121
HUMORAHEACEN1774290394
Humana and Centerwell Hit by Clop Ransomware Attack in August 2025 Humana confirmed a data breach in August 2025, exposing sensitive personal and medical information of an undisclosed number of individuals. Compromised data includes names, Social Security numbers, medical billing details, claims info, provider names, Humana ID numbers, patient account numbers, and health insurance data. Subsidiary Centerwell also began notifying affected individuals this month, with Texas reporting 4,618 impacted residents. The cybercriminal group Clop claimed responsibility for the breach, though Humana has not confirmed the attribution. The attack stemmed from a vendor’s software vulnerability, which Clop has exploited in other incidents, including a flaw in Oracle’s E-Business Suite. Humana is offering affected individuals 24 months of free credit monitoring and identity restoration services through Equifax, with an enrollment deadline of March 31, 2027. Clop, active since 2019, specializes in zero-day exploits and often steals data without encryption, demanding ransom to prevent leaks. In 2025, the group claimed 456 attacks, with 35 confirmed, including breaches at Parexel International and Barts Health NHS Trust. The Oracle vulnerability alone accounted for 119 claims, 29 of which were verified. The breach adds to a rising trend of ransomware attacks on U.S. healthcare entities. Comparitech recorded 31 confirmed attacks in 2025 on non-direct-care healthcare businesses, exposing data of over 196 million people. Other recent incidents include breaches at Catalyst RCM (claimed by Everest) and Resource Corporation of America (targeted by Medusa for an $800,000 ransom). Humana, the fourth-largest U.S. health insurer, has faced prior scrutiny over fraud allegations and AI-driven Medicare claim denials. Centerwell, its subsidiary, provides pharmacy, senior care, and home health services. Both companies now face a class-action lawsuit alleging inadequate data protection.
INCIDENT DETAILS -
TYPE
Ransomware Attack
MOTIVATION
Financial gain (ransom demand)
IMPACT
Data Compromised: Sensitive personal and medical informationBrand Reputation Impact: YesLegal Liabilities: Class-action lawsuitIdentity Theft Risk: High
DATA BREACH
NamesSocial Security numbersMedical billing detailsClaims infoProvider namesHumana ID numbersPatient account numbersHealth insurance dataNumber Of Records Exposed: Undisclosed (4,618 Texas residents confirmed)Sensitivity Of Data: High (PII and PHI)Data Exfiltration: YesData Encryption: No (Clop typically steals data without encryption)Personally Identifiable Information: Yes
JULY 2025
628Before Incident
AUGUST 2023
587Before Incident
Breach
09 Aug 2023Humana
Humana Inc

Humana Inc Data Breach

527After Incident
MEDIUM-60
HUM143072625
The Maine Office of the Attorney General reported on October 24, 2023, that Humana Inc experienced a data breach on August 9, 2023, due to unauthorized access to their document processing system, affecting 2,844 individuals in total, including 16 residents. The breached information included names, Humana identification numbers, provider names, and service dates.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
namesHumana identification numbersprovider namesservice datesdocument processing system
DATA BREACH
namesHumana identification numbersprovider namesservice datesnamesHumana identification numbers
MAY 2023
597Before Incident
Cyber Attack
30 May 2023Humana
Humana, Inc.

Humana (Welltok, Inc.) Cyberattack Involving Malware

577After Incident
CRITICAL-20
HUM030090625
On May 30, 2023, Humana, Inc. (via its subsidiary Welltok, Inc.) fell victim to a malware-based cyberattack, exposing sensitive data of 33,193 Washington State residents. The breach compromised personal identifiers—including full names, dates of birth, health insurance policy/ID numbers, and medical information. The incident highlights a severe data security failure, where attackers exploited vulnerabilities to access protected health information (PHI). Such exposure poses risks of identity theft, medical fraud, and targeted phishing, as the leaked data could enable malicious actors to impersonate victims for financial or healthcare-related scams. The breach also undermines trust in Humana’s ability to safeguard patient confidentiality, potentially leading to regulatory penalties under laws like HIPAA (Health Insurance Portability and Accountability Act). While the attack did not involve ransomware, the scale and sensitivity of the leaked data—particularly medical records—elevate its severity. The compromised information could have long-term repercussions for affected individuals, including discrimination risks (e.g., based on pre-existing conditions) or unauthorized access to healthcare services. Humana’s response, including notification and mitigation measures, remains critical to limiting further harm.
INCIDENT DETAILS -
TYPE
Cyberattack (Malware)
IMPACT
NamesFull dates of birthHealth insurance policy or ID numbersMedical informationIdentity Theft Risk: High (PII and medical data exposed)
DATA BREACH
Personally Identifiable Information (PII)Protected Health Information (PHI)Number Of Records Exposed: 33,193Sensitivity Of Data: HighNamesFull dates of birthHealth insurance policy or ID numbers
SEPTEMBER 2022
612Before Incident
Breach
01 Sep 2022Humana
Humana

Humana Data Breach Incident

560After Incident
CRITICAL-52
HUM232025922
Humana suffered a data breach incident after Choice Health, one of the companies it uses to help sell its products, experienced a cyberattack. The breach exposed some customers’ first and last names, Social Security numbers, Medicare beneficiary identification numbers, dates of birth, addresses, contact information and health insurance information. Humana sent out data breach letters to all affected parties, informing them of the incident and the ways to protect themselves from fraud.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
first and last namesSocial Security numbersMedicare beneficiary identification numbersdates of birthaddressescontact informationhealth insurance information
DATA BREACH
PIIHealth InformationSensitivity Of Data: Highfirst and last namesSocial Security numbersMedicare beneficiary identification numbersdates of birthaddressescontact information
MAY 2022
655Before Incident
Breach
07 May 2022Humana
Humana Inc.

Humana, Inc. Data Breach (2022)

599After Incident
CRITICAL-56
HUM033091825
Humana, Inc. experienced a data breach on May 7, 2022, due to unauthorized access to its systems. The incident exposed sensitive personal information of 639 Washington State residents, including names, Social Security numbers, and health insurance details. The breach was formally reported to the Washington State Office of the Attorney General on September 8, 2022, indicating a delayed discovery or disclosure. The compromised data poses significant risks, such as identity theft, financial fraud, and potential misuse of health-related information. While the exact method of unauthorized access was not specified, the exposure of Social Security numbers—a high-value target for cybercriminals—heightens the severity. The breach underscores vulnerabilities in Humana’s data protection measures, raising concerns about compliance with regulatory standards like HIPAA and the potential for long-term reputational damage.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
namesSocial Security numbershealth insurance informationIdentity Theft Risk: High (PII exposed)
DATA BREACH
Personal Identifiable Information (PII)Protected Health Information (PHI)Sensitivity Of Data: HighData Exfiltration: YesnamesSocial Security numbers
APRIL 2021
723Before Incident
Ransomware
17 Apr 2021Humana
Humana

Humana Data Breach via PracticeMax Ransomware Attack

616After Incident
CRITICAL-107
HUM511080425
The Maine Office of the Attorney General reported on September 28, 2021, that Humana experienced a data breach involving a ransomware attack on PracticeMax. The breach occurred from April 17, 2021, to May 5, 2021, and potentially affected 4,424 individuals, involving unauthorized access to Protected Health Information (PHI). PracticeMax has offered credit monitoring services for a minimum of 12 months to affected individuals.
INCIDENT DETAILS -
TYPE
Data Breach, Ransomware
IMPACT
Data Compromised: Protected Health Information (PHI)
DATA BREACH
Type Of Data Compromised: Protected Health Information (PHI)Sensitivity Of Data: High
OCTOBER 2020
767Before Incident
Breach
12 Oct 2020Humana
Humana Inc.

Humana Inc Data Breach

713After Incident
HIGH-54
HUM806072625
The California Office of the Attorney General reported that Humana Inc experienced a data breach involving the disclosure of personal information by an employee of a subcontractor on March 8, 2021. The breach date occurred between October 12, 2020, and December 16, 2020, potentially affecting member details, including names and birthdates.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
NamesBirthdates
DATA BREACH
Personal InformationNamesBirthdates
MAY 2018
794Before Incident
Breach
30 May 2018Humana
Humana Inc.

Humana Inc Data Breach

744After Incident
HIGH-50
HUM1046072525
The California Office of the Attorney General reported a data breach involving Humana Inc on January 3, 2019. The breach occurred between May 30 and September 13, 2018, due to unauthorized access to employee system credentials at Bankers Life, potentially affecting personal information of individuals who applied for Humana health insurance policies.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Personal Information
DATA BREACH
Type Of Data Compromised: Personal Information

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Humana ?
?
What was Humana's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Humana's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Humana's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Humana's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Humana's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Humana's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Humana's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Humana's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Humana's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Humana's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Humana's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Humana's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Humana ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Humana's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Humana Cyber Scoring History | Rankiteo