Minnesota Health Insurance Network Data Breach–What You Need to Know & What to Do Next
Overview
Minnesota Health Insurance Network reported a cybersecurity incident after the Akira ransomware group claimed responsibility for an attack in April 2026. The incident potentially exposed client and employee personal information, including highly sensitive data such as passport information, contact details, and financial records.
Minnesota Health Insurance Network, also known as MNHI, is a health insurance brokerage firm that has been serving Minnesota residents since 1994. The company is a member of the Minnesota Association of Health Underwriters (MAHU) and maintains an A+ rating with the Better Business Bureau. MNHI works with most of Minnesota’s major health insurance companies, including BlueCross BlueShield of Minnesota, Medica, HealthPartners, PreferredOne, UCare, Humana, Cigna, Aetna, SilverScript, and others.
The company specializes in helping individuals, families, and small business owners find health insurance coverage, offering a wide range of products including individual and family health insurance, Medicare supplement insurance, small business and small group health insurance, dental insurance, life and disability insurance, and international travel and medical insurance.
According to ransomware threat intelligence, the Akira ransomware group posted Minnesota Health Insurance Network to its data leak site on April 9, 2026. The threat actors claim to have exfiltrated approximately 23 GB of corporate data and state they will “upload 23gb of corporate data soon.” The posting describes the stolen data as including client and employee personal information such as passports, addresses, phones, emails “and so on,” as well as projects, financials, contracts and agreements.
Akira has been identified as one of the most prolific ransomware groups targeting healthcare organizations and related businesses in 2025 and 2026. The group typically uses double-extortion tactics, stealing data before encrypting systems to maximize pressure on victims to pay ransoms.
What Information May Have Been Exposed In the Minnesota Health Insurance Network Data Breach?
According to the threat actors’ claims, the potentially compromised data includes a significant amount of highly sensitive personal and business information. Client personal information reportedly exposed includes passport information, home addresses, phone numbers, and email addresses. Similar employee personal information was also allegedly compromised.
The breach also reportedly exposed business-critical data including project information, financial records, contracts, and agreements. Given Minnesota Health Insurance Network’s role as a health insurance broker, the compromised data may also include health insurance application information, policy details, and other sensitive information related to clients’ insurance coverage.
The exposure of passport information is particularly concerning, as passports are government-issued identification documents that can be used for identity theft and fraud. Combined with contact information and other personal details, this data creates significant risks for affected clients and employees.
Because MNHI works with individuals seeking health insurance coverage, the breach may also involve information about clients’ health status, pre-existing conditions, or other medical information that was provided during the insurance application process.
How Minnesota Health Insurance Network Responded to the Breach?
As of this writing, Minnesota Health Insurance Network has not issued a public statement regarding the alleged ransomware attack. The company has not confirmed the incident or provided details about its investigation, the scope of affected individuals, or steps being taken to notify those whose data may have been compromised.
Organizations affected by ransomware attacks typically engage cybersecurity forensics experts to investigate the incident, contain the threat, and determine the full nature and scope of data accessed. Insurance brokers that experience breaches involving personal information are required to notify affected individuals and state regulators within specified timeframes under various state data breach notification laws.
Minnesota has a data breach notification law that requires organizations to notify affected residents when their personal information has been compromised. If the breach is confirmed to involve the data of Minnesota residents, MNHI would be required to provide timely notification to affected individuals.
How to Check If Your Personal Info Is Exposed
If you are a current or former client of Minnesota Health Insurance Network (MNHI), your personal information may have been exposed in this breach. This includes individuals who have obtained health insurance quotes, purchased health insurance policies, or otherwise worked with MNHI for insurance services.
Employees of Minnesota Health Insurance Network may also be affected by the breach, as the threat actors specifically mentioned employee personal information in their posting.
Monitoring your accounts, reviewing credit reports, and watching for any notification letters from MNHI are all crucial steps in assessing your potential exposure. Given that passport information was allegedly stolen, affected individuals should also monitor for signs of identity theft and consider reporting the potential compromise to the U.S. Department of State.
What You Can Do If Your Information Was Exposed
If your personal information may have been part of the Minnesota Health Insurance Network breach, you should take immediate protective action. Review your financial accounts, credit card statements, and medical explanation of benefits forms for any unfamiliar activity. Update account passwords, particularly for any health insurance portals or accounts where you may have reused passwords.
Given the exposure of passport information, addresses, and contact details, consider placing a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, and TransUnion). A credit freeze prevents new accounts from being opened in your name, while a fraud alert requires creditors to take extra steps to verify your identity before extending credit.
If your passport information was compromised, you may want to contact the U.S. Department of State to report the potential theft and consider obtaining a new passport. Monitor for any suspicious activity that could indicate someone is attempting to use your passport information.
Be particularly vigilant for phishing attempts following this breach. Scammers may use the stolen contact information to send emails, texts, or make phone calls pretending to be from insurance companies, government agencies, or other trusted organizations. Acting now can limit the long-term consequences of this breach and protect your personal and financial information in the future.
Understanding Your Legal Rights: Data Breach Lawyer Near Me
Victims of data breaches may be entitled to legal remedies if a company did not adequately safeguard their personal information. Insurance brokers have a duty to protect the sensitive personal, medical, and financial information they collect from clients during the insurance application and enrollment process.
Almeida Law Group is actively reviewing the Minnesota Health Insurance Network incident to determine what legal options may be available for those affected.
If you are a client or employee of Minnesota Health Insurance Network and believe your information may have been exposed in this breach, you can contact Almeida Law Group for a free consultation.