The CareFirst BlueCross BlueShield Data Breach: Reported Filing Facts
CareFirst BlueCross BlueShield is a prominent health insurance company that provides comprehensive medical coverage and manages complex health benefits for millions of members. In the course of its operations, the company collects and maintains highly sensitive personal information, including detailed health records, insurance policy details, and government-issued identification numbers required for claims processing and coverage administration. This data breach was officially reported to the Maryland Attorney General in 2025, confirming that unauthorized access to protected systems occurred. If you have received a formal data breach notification letter from CareFirst, it indicates that your personal or health-related information was potentially compromised. We recommend reviewing the letter carefully to understand the specific scope of the incident and the identity protection services being offered.
- State
- Maryland
- Reported
- March 5, 2025
What to do if you were affected
These general steps can help limit the risk of identity theft and fraud after any data breach.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Related data breach cases
- St. Joseph College of Maine
- Tokyo Electron U.S. Holdings, Inc.
- Kinsey's Archery Products, Inc.; VUC, Inc.
- VUC, Inc.
- Open Door Capital, LLC
- Clarke Nicolini & Associates, Ltd.
- Crown Health Care Laundry Services
- OrthoMinds, LLC
- CSG Consultants
- Miedema Produce, Inc.
- Forum Communications Company
- CareFirst BlueCross Blue Shield
- Strauss Brands LLC
- Uni-Select