← Cotiviti

2020 Cotiviti / Humana — Visionary Medical subcontractor insider-style mis-upload; ~63–65k members’ PHI

2020 65.0K records affected Share on X

Data compromised

Humana member PHI categories described in healthcare breach summaries—identifiers plus clinical/claims-adjacent context per notices

Technical writeup

Between mid-October and mid-December 2020, a Visionary Medical Systems subcontractor working on Humana medical-record workflows for analytics vendor Cotiviti copied PHI into a personal Google Drive for impermissible “training,” exposing roughly 63,000–65,000 plan members per HIPAA Journal, TechTarget, and DataBreaches.net summaries of the ensuing class-action settlement (August 2022). The episode is best classified as insider / vendor misuse of authorized access rather than external ransomware.

Root cause

Contractor mishandling—unauthorized storage of customer PHI in personal cloud storage

References