In November 2024, MedicareCompareUSA, a licensed insurance agency and call center that assists consumers in comparing and enrolling in Medicare plans, discovered suspicious activity related to certain internal email accounts. Findings revealed that unauthorized access occurred between Nov. 5, 2024, and Nov. 21, 2024 and personal and protected health information was potentially exposed.
On March 18, 2025, MedicareCompareUSA notified Humana that individuals related to the insurer were potentially involved in the data breach. Compromised information includes names, dates of birth, Social Security numbers, driver's license or state ID numbers, health insurance information, Medicare information and financial account information.
The breach is considered severe, due to the combination of exposed data, which increases the risk of identity theft and medical fraud for those impacted. The total number of affected individuals has not been released, but multiple health insurance organizations were impacted.
MedicareCompareUSA disclosed the data breach to the Washington Attorney General's office on May 12, 2025, reporting 922 residents affected. Both MedicareUSA and Human published a Notice of Privacy Incident on their own websites.
MedicareCompareUSA began notifying impacted individuals in writing on May 12, 2025 and is offering 12 free months of TransUnion Cyberscout single bureau credit monitoring services to affected individuals.
If you receive a notice from MedicareCompareUSA or Humana about this breach, you may want to:
The organization has also set up a hotline for individuals with questions at 1-833-998-8824 from 9:00 a.m. Eastern to 8:00 p.m. Eastern, Monday through Friday.
For more details about MedicareCompareUSA and its services, visit the company’s website.
A breach notice means your personal details could be circulating far beyond the organization involved. One practical step is continuous monitoring: services such as Identity Defender (included with an ExpressVPN subscription) can automatically check dark-web markets, flag new credit-file activity, and request removal of your information from data-broker sites.
This kind of “early-warning system” can’t undo a breach, but it can help you spot misuse quickly and limit further exposure. ExpressVPN is offering 61% off, risk-free for 30 days, with ID Theft Insurance included and no extra cost for those who sign up for one or two years.