JUN 25, 2010 12:13pm ET

Related Links

eHealth Initiative Studies the I.T. of ACOs
February 10, 2012
Rule to Ease Consumer Understanding of Health Insurance Policies
February 9, 2012
New Content on HHS Consumer Web Sites
February 8, 2012
Health Plan ID, Insurance Exchange Rules Coming Soon
February 6, 2012
Aetna Wants Dentists to Push Smoking Cessation via iPads
January 31, 2012
HIT Vendor Round-up: Castlight, MedAssets & Aprima
January 31, 2012
Laptop Loaded with PHI Stolen from Lexington Clinic
January 31, 2012

Web Seminars

The Evolution of Tablet Computing in Healthcare
Available On Demand
Which comes first? Chargemaster Standardization vs. System Conversion
Available On Demand
Chronic Care. Chronic I.T. Challenges
Available On Demand

Big Breach at Anthem Blue Cross

Print
Reprints
Email

Anthem Blue Cross, the trade name for Blue Cross of California, is notifying about 230,000 members and applicants for insurance that a Web site used to apply for individual health insurance policies was breached.

The insurer says attorneys working on a class action lawsuit were able to access medical information and credit card and Social Security numbers, among other information, because all security mechanisms were not reinstated following an October 2009 upgrade.

An attorney representing affected individuals told the Associated Press that the information was not secure for five months. What follows is a statement that Anthem Blue Cross has issued:

"Anthem Blue Cross is committed to protecting the privacy and security of our members' and applicants' personal information, in accordance with all applicable laws and regulations.

"We recently learned of a situation in which a small number of individuals manipulated the web address (URL) within the web site we use to allow people applying for individual insurance to track the status of their insurance applications. Through this manipulation, some of these individuals gained unauthorized access to certain private information. The vast majority of such manipulation and the resulting unauthorized access occurred at the hands of certain attorneys (representing an applicant).  We believe that this manipulation was conducted to support a class action against Anthem Blue Cross and/or its parent company - over the very breach being committed.

"The ability to manipulate the web address (URL) was available for a relatively short period of time following an upgrade to the system. After the upgrade was completed, a third party vendor validated that all security measures were in place, when in fact they were not. As soon as the situation was discovered, we made the necessary security changes to prevent it from happening again.

"We have requested both by letter and in court filings that the attorneys return all information improperly obtained from the individual application system and as a result, that information has been delivered to a court approved custodian who will ensure its security.

"We have worked since discovery of this matter to analyze the data in an effort to identify all individuals whose information may have been impacted and prepared to communicate directly to affected members and applicants as soon as possible. As stated above, all information acquired by the attorneys has been transferred to the court's custodian and beyond that, we have received no indication that any other information accessed has been used inappropriately.

"Out of abundance of caution, all appropriate applicants will receive a detailed notification from Anthem Blue Cross explaining what happened, and will be offered identity protection services for one year at no cost.

"We are currently weighing our legal options with respect to the data, the impact - if any - on our members, and the remediation costs incurred as a result of these actions."

 

Comments (0)

Be the first to comment on this post using the section below.

Add Your Comments:
You must be registered to post a comment.
Not Registered?
You must be registered to post a comment. Click here to register.
Already registered? Log in here
Please note you must now log in with your email address and password.
Twitter
Facebook
LinkedIn

A major success factor for accountable care organizations will be linking caregivers across the spectrum of care delivery. If history is any indication, that's going to be an industrywide struggle.

Login  |  My Account  |  White Papers  |  Web Seminars  |  Events |  Newsletters |  eBooks
FOLLOW US
Already a subscriber? Log in here
Please note you must now log in with your email address and password.