banner Expire 1 October 2024
Ad Ends 13 October 2024
ad End 18 October 2024
banner Expire 1 November 2024
banner Expire 18 October 2024
banner Expire 20 October 2024
Ad Ends 13 October 2023
What's new
banner Expire 15 October 2024
Kfc CLub
Western union transfer
CrdCrew.cc Carding forum
UniCvv
Ad expire at 5 August 2024
Carding.pw carding forum
adv exp at 23 August 2024

Health Insurer Fined $5.1m Over Data Breach

File_closed07

TRUSTED VERIFIED SELLER
Staff member
Joined
Jun 13, 2020
Messages
7,018
Reaction score
908
Points
212
Awards
2
  • trusted user
  • Rich User
An American health insurer has agreed to pay $5.1m to the Office for Civil Rights (OCR) at the US Department of Health and Human Services (HHS) to settle potential violations of the Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security Rules.

The agreement entered into by Excellus Health Plan, Inc. relates to a data breach that lasted 17 months and affected over 9.3 million people.

Excellus is a New York–based health services corporation that provides health insurance coverage to over 1.5 million people in upstate and western New York.

A breach report filed by Excellus on September 9, 2015, stated that cyber-attackers had gained unauthorized access to the company's information technology systems.

The breach began on or before December 23, 2013, and dragged on until May 11, 2015. After gaining entry to the company's systems, malicious hackers installed malware and conducted reconnaissance activities that ultimately resulted in the disclosure of protected health information (PHI) of more than 9.3 million individuals.

Information exposed in the attack included names, addresses, dates of birth, email addresses, Social Security numbers, bank account information, health plan claims, and clinical treatment information.

Plans affected by the breach were BlueCard Members; BlueCross BlueShield of Central New York; BlueCross and BlueShield of the Rochester area; BlueCross BlueShield of Utica-Watertown; and Excellus BlueCross BlueShield.

OCR’s investigation into the security incident found potential violations of the HIPAA rules, including failures to implement risk management, information system activity review, and access controls and failure to conduct an enterprise-wide risk analysis.

“Hacking continues to be the greatest threat to the privacy and security of individuals’ health information. In this case, a health plan did not stop hackers from roaming inside its health record system undetected for over a year, which endangered the privacy of millions of its beneficiaries,” said OCR director Roger Severino.

“We know that the most dangerous hackers are sophisticated, patient, and persistent. Health care entities need to step up their game to protect the privacy of people’s health information from this growing threat.”

In addition to paying a sizable monetary settlement, Excellus has agreed to undertake a corrective action plan that includes two years of monitoring.
 
Ad End 1 October 2024
Top