Milliman

Milliman

Many schools and universities received benefits for university staff retirement through the Teachers Insurance and Annuity Association of America ("TIAA"). The TIAA portion of the intrusion did not directly target the vendor's computer systems. Pension Benefit Information, TIAA's vendor, informed TIAA that the intrusion had affected PBI.

PBI informed HHS that 1,209,825 patients or insurance holders of its HIPAA-covered clients had been impacted, while Milliman Solutions informed the Maine Attorney General's Office that the attack on PBI had affected 1,280,823.

At CalPers, Genworth Financial, and Wilton Reassurance, an estimated extra 5 million people have been impacted, according to earlier press reports. Even yet, they do not represent an exhaustive list or an estimate of all the clients of PBI whose consumers were impacted.

They took it seriously and took preventive steps to secure it.

PIB also offered access to 24 months of complimentary identify monitoring services through Kroll.

Source: https://www.databreaches.net/teachers-insurance-and-annuity-association-of-america-notifying-2630717-after-pbi-alerts-them-to-moveit-breach/

TPRM report: https://scoringcyber.rankiteo.com/company/milliman

"id": "mil24124723",
"linkid": "milliman",
"type": "Data Leak",
"date": "07/2023",
"severity": "85",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'customers_affected': '1,209,825',
                        'industry': 'Financial Services',
                        'name': 'Pension Benefit Information (PBI)',
                        'type': 'Vendor'},
                       {'customers_affected': '1,280,823',
                        'industry': 'Financial Services',
                        'name': 'Milliman Solutions',
                        'type': 'Client'},
                       {'customers_affected': '5,000,000',
                        'industry': 'Financial Services',
                        'name': 'CalPers',
                        'type': 'Client'},
                       {'customers_affected': '5,000,000',
                        'industry': 'Financial Services',
                        'name': 'Genworth Financial',
                        'type': 'Client'},
                       {'customers_affected': '5,000,000',
                        'industry': 'Financial Services',
                        'name': 'Wilton Reassurance',
                        'type': 'Client'},
                       {'industry': 'Financial Services',
                        'name': 'TIAA',
                        'type': 'Client'},
                       {'industry': 'Healthcare',
                        'name': 'HHS',
                        'type': 'Client'}],
 'data_breach': {'number_of_records_exposed': '1,209,825',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Pension Benefit Information',
                                              'Personally Identifiable '
                                              'Information']},
 'description': 'A data breach at Pension Benefit Information (PBI) affected '
                'millions of individuals, including clients of TIAA, HHS, '
                'Milliman Solutions, CalPers, Genworth Financial, and Wilton '
                "Reassurance. The breach did not directly target TIAA's "
                'systems but affected PBI, a vendor of TIAA. PBI informed HHS '
                'and Milliman Solutions of the impact, and preventive measures '
                'were taken. Complimentary identity monitoring services were '
                'offered to affected individuals.',
 'impact': {'data_compromised': ['Pension Benefit Information',
                                 'Personally Identifiable Information'],
            'identity_theft_risk': 'High'},
 'references': [{'source': 'Press Reports'}],
 'regulatory_compliance': {'regulatory_notifications': ['HHS',
                                                        'Maine Attorney '
                                                        "General's Office"]},
 'response': {'enhanced_monitoring': '24 months of complimentary identity '
                                     'monitoring services',
              'third_party_assistance': 'Kroll'},
 'title': 'Data Breach at Pension Benefit Information (PBI)',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.