Menu
Browse

Cyber Incident Victim: Arizona Complete Health

Date:

Jan 2021

Location:

United States of America

Summary

Arizona Complete Health experienced a data breach stemming from a cyberattack on its third-party file-sharing vendor, Accellion, where unauthorized actors accessed files containing member information. The compromised data included names, addresses, dates of birth, insurance identification numbers, and health details such as medical conditions and treatment information. The organization terminated its relationship with Accellion, removed all data from the vendor's systems, and initiated an internal review of data-sharing protocols. While no evidence of misuse was identified, affected individuals were offered complimentary credit monitoring and identity theft protection services for one year. Law enforcement, including the FBI, was engaged to investigate the incident.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 3 motives 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

Arizona Complete Health (AzCH) was notified on January 25, 2021, that its file-sharing vendor Accellion had suffered a cyber-attack compromising member data. The breach occurred between January 7 and January 25, 2021, when an unauthorized actor accessed AzCH files stored on Accellion's system. The attacker potentially viewed or exfiltrated files containing protected health information exchanged between AzCH and healthcare providers. Exposed data included member names accompanied by addresses, dates of birth, insurance identification numbers, and medical details such as diagnoses and treatment histories. AzCH confirmed the incident stemmed from unauthorized access to Accellion's infrastructure rather than AzCH's own systems.

Cyber Incident Image

Upon discovery, AzCH initiated response measures including collaboration with Accellion to investigate the breach scope and forensic analysis of compromised files. The organization terminated its relationship with Accellion, removing all data from the vendor's systems. AzCH reviewed its data-sharing protocols to prevent similar incidents while Accellion engaged law enforcement agencies including the FBI. Although no evidence indicated misuse of stolen data, AzCH offered affected members one year of complimentary credit monitoring and identity theft protection services. The health plan advised members to review insurance statements for unauthorized transactions and provided instructions for implementing credit freezes or fraud alerts through a supplemental identity protection guide distributed with breach notification letters.

Sources
Sources available to members
2 sources