Humana's Two Data Breaches in Two Months Both Trace to Third Parties

Humana disclosed two data breaches in two months, and a third followed. None started on Humana's own network — each traced to a third party holding member data. The real story is healthcare's business-associate concentration risk, not a firewall that failed.

Share
A white medical shield icon with a neon purple EKG line that shatters in the center on a teal background.

When a health insurer discloses two data breaches inside roughly two months, the instinct is to read it as a security team that keeps getting beaten. Humana's spring-2026 disclosures tell a more specific story. Neither breach started inside Humana's own network. One came through a vulnerability in a vendor's Oracle software; the other came through a law firm Humana had hired. The recurring failure is not a firewall — it is the number of outside parties holding copies of the same permanent patient data.

Humana is one of the largest health insurers in the United States, and like every insurer at that scale it does not keep member data to itself. It ships names, Social Security numbers, claims records and treatment histories to software vendors, analytics partners and outside counsel as a routine cost of running the business. Each of those relationships is a door — and in 2026 attackers walked through several of them.

  ONE DATA SET, MANY DOORS
The same Humana member records sit with dozens of outside parties — each an independent way in.
THE STRUCTURAL FACT
Names, Social Security numbers, claims and treatment data are copied out to vendors, law firms and analytics partners to run the business.
DOOR 1 — A VENDOR'S CODE
Attackers reach Humana's internal systems through a vulnerability in Oracle software — part of a mass supply-chain campaign.
DOOR 2 — OUTSIDE COUNSEL
Social engineering opens a law firm's file server holding litigation discovery data Humana had handed over.
DOOR 3 — AN AI PARTNER
A phishing attack on analytics vendor Xsolis exposes ~1.4M patients across its clients, Humana members among them.
THE OUTCOME
Durable identity data — SSNs, DOBs, health history — is out, and unlike a password it cannot be reset.
Source: Humana / vendor breach notices; Texas AG filings; Comparitech and Cybernews reporting, 2025–2026.

Breach One: A Vendor's Oracle Flaw

The breach that drew the most attention is the one Humana tied to a third-party software problem. Per the company's notices and reporting from Comparitech, unauthorized access to certain Humana internal systems occurred in August 2025 through a vulnerability in a vendor's Oracle software. Humana says it discovered the intrusion on September 29, 2025, and began notifying affected people in the spring of 2026 — a months-long gap that puts real weight on what the notification laws actually require.

The exposed fields are the durable kind: names, Humana ID or patient-account numbers, Social Security numbers, medical billing and claims information, dates of service, provider names and other health-insurance details. State breach filings put the confirmed count at at least 4,618 Texas residents, with customers in five other states also affected; Humana has not published a nationwide total. Multiple outlets have linked the intrusion to the Clop ransomware group's mass exploitation of an Oracle E-Business Suite zero-day (CVE-2025-61882) that hit dozens of large organizations in late 2025, though Humana itself has not attributed the breach to any named actor.

Breach Two: The Law Firm Humana Hired

The second incident had nothing to do with Oracle and everything to do with a habit early coverage glossed over: sensitive data leaves the building the moment a company hands it to its lawyers. A threat actor used social engineering to gain access to a file server at Pillsbury Winthrop Shaw Pittman, an outside law firm, where litigation discovery materials Humana had produced were stored. Those files contained names, Social Security numbers and health-insurance information; state filings identified roughly 2,100 affected Texas residents, and the firm has since been sued by breach victims.

Precision matters here. Early coverage speculated the breaches “likely” came from a compromised sub-vendor or a credential attack, and framed the pair as Humana's security failing twice. What Humana actually disclosed is narrower and more instructive: two different third parties, two different failure modes — a supply-chain software flaw and a human-factor compromise at a law firm — reaching the same category of member data.

And Then a Third Door

If the two-breach framing looked like a coincidence in April, the months since made the pattern harder to dismiss. In June 2026, healthcare analytics vendor Xsolis disclosed a breach affecting roughly 1.4 million patients across the 600-plus organizations it serves — a client list that includes Humana and Mayo Clinic Health System. The root cause was a January 2026 phishing attack on Xsolis, not on any of its customers. Humana did nothing wrong in that incident in the conventional sense; its members' data was exposed anyway, because it lived on a partner's systems.

My Read

The honest headline is not “Humana keeps getting breached.” It is that a modern insurer's attack surface is mostly other people's networks. Under HIPAA these outside parties are business associates, and a large insurer can have hundreds of them — each with a copy of member records, each with its own security posture, each a place a breach can start without a single Humana control failing. That is the concentration risk healthcare has quietly built: not one fortress to defend, but a sprawling supply chain where the weakest vendor sets the floor.

This is also why health data is the target it is. A breached password is a nuisance you rotate in an afternoon. A Social Security number, date of birth and medical history are effectively permanent — they cannot be reissued, and they fuel identity fraud and insurance scams for years. That durability is exactly what makes a healthcare data breach more valuable to an attacker, and more expensive to the victim, than almost any other kind. Read that way, Humana's cluster of incidents is less a story about one company's defenses and more a signal about an entire sector's governance: when the same records sit behind dozens of unequal doors, repetition is the expected outcome, not the surprise.

What Defenders Should Do

The Humana cluster is a business-associate problem, so the fixes live mostly in vendor governance rather than the SOC:

  • Map where your regulated data actually lives. Inventory every vendor, law firm and analytics partner that holds PII or PHI, and treat that list — not just your own network diagram — as your real attack surface.
  • Put teeth in business-associate agreements. Require breach-notification timelines, minimum security controls, evidence of patching (the Oracle flaw was fixable), and the right to audit. A signed BAA that no one verifies is paperwork, not risk management.
  • Minimize what you hand over. Send counsel and vendors the least data that does the job, redact SSNs in discovery where you can, and set deletion deadlines. Data a partner never holds cannot leak from the partner.
  • Rehearse HIPAA breach notification before you need it. Know your obligations under the Breach Notification Rule and the state clocks, including breaches that originate at a business associate, so the 60-day windows do not catch you flat-footed.
  • Assume the durable data is already out. Since SSNs and health histories cannot be reset, shift toward fraud monitoring, identity-theft support for members, and detection of misuse — not just prevention that a vendor can undo for you.

Open Questions

Several specifics remain unconfirmed. Humana has not published a nationwide total for the Oracle-linked breach, so the true scale beyond the state-level Texas figures is unknown. The Clop/CVE-2025-61882 attribution comes from security reporting and the group's own claims, not from Humana. It is also not fully established how much overlap exists between the member populations hit across the vendor, law-firm and Xsolis incidents, or whether regulators will treat the cluster as evidence of a systemic remediation failure. Where the record is thin, this account relies on Humana's and its vendors' own breach notices and state attorney-general filings rather than inference.

Primary Documents

Read more