Public Health Insurance

Search This Blog

Showing posts with label Breach. Show all posts
Showing posts with label Breach. Show all posts

Anthem Blue Cross CA Security Breach Update Pt IV

Further updates regarding the security breach of Anthem's online application tracker program.

As of today, 470,000 individual subscribers have been notified of a potential compromise. 230,000 are in California, the rest across the various Anthem states.

There are some disturbing bits of information surfacing.

Apparently the breach went on for quite some time and was only discovered in March when an attorney who breached the system filed a class action lawsuit regarding the breach. I have at least two clients who were breached as far back as November, 2009.

Perhaps the most troubling is that, according to the Atlanta Journal-Constitution, a company investigation has yet to identify 10 computer addresses (IPs) that accessed information. This is of concern as this would indicate that these 10 breaches were not conducted by the attorney(s) and are IP addresses of unknown hackers.

I will update when I receive additional information. Questions for California subscribers should be addressed to Anthem individual membership at 800-333-0912.

Some current press articles on the Wellpoint/Anthem breach:

Reuters

Associated Press

My ZimbioMy Ping in TotalPing.com

Anthem Security Breach Update

Article from the Orange County Register indicating that more than 200,000 affected so far by the security breach of the Anthem Blue Cross Online Application Tracker.

Orange County Register Article

According to the article, the attorneys who breached the system have returned all of the improperly obtained private information to a custodian of the court system. I expect that means that everyone who was affected by the breach can be assured that their private information is now safeguarded.

For clarification to the majority of my clients, this security breach does not impact HIPAA applications (nor small group). The application tracker program allows applicants (and apparently others) for individual & family plans to view a PDF of the electronic application. This PDF file contains the full application information including PHI and financial information.

HIPAA applications, like other "paper" applications, are not rendered to PDF for viewing and list on agent services as "application not submitted online -- not available for viewing". They are also not eligible for the application tracker program even though an e-mail is generated indicating it's availability.

My ZimbioMy Ping in TotalPing.com

Anthem Security Breach Update

I have a couple of updates regarding the security breach of the Anthem Blue Cross "Application Tracker" system.

1. Anyone who submitted an application for a minor child/children only that was breached and has received ID theft protection for the minor(s) will, if there was information breach for the parent/guardian, also receive the protection. Anthem is currently sorting applications on minors-only to determine if any breach of the parent/guardian information also occurred. This may take a bit of time as the original determinations were made based on the applicants. Anthem will have to research applications in full to determine who else may have had PHI or private information compromised in regard to that application. You can contact member services at 800-333-0912 at Anthem Blue Cross for assistance.

2. It is important to bear in mind that, while Anthem Blue Cross has ultimate responsibility with regard to this hacker manipulation, the responsible party(s) is/are mainly attorneys who are looking to file a law suit against Anthem. Yes, the carrier is ultimately responsible for 100% security of your information, as are we agents.

3. I have never really understood the need for an "application tracker" program in the first place. Anthem has provided this "link" to track you own application online and, unfortunately, this is an unintended result. The application generates e-mail updates (which are secure) at any change of application status for any applicant who provides a valid e-mail address. Since you have to provide a valid e-mail address and select opt-in on e-mail notification to even receive the application tracker link, you will automatically receive the e-mail updates anyway. Unless you have a burning desire to view the PDF of your application, anything else will automatically be communicated by secure e-mail, thus rendering the application tracker program redundant.

This hack was not of an agent's database or agent log in access to the insurance company web site. This hack was on a program designed to let anyone who applies for individual coverage online with Anthem to track their own application. It is not necessary unless you have applied direct with the carrier since your independent agent will be monitoring progress and advising you (or should be!).

My ZimbioMy Ping in TotalPing.com

Anthem Blue Cross Security Breach (Individual Health)

Anyone who has recently applied for individual health insurance with Anthem Blue Cross and been assigned an online application tracker link needs to be aware of the following unauthorized security breach. Affected applicants will receive notification with details and one year of free identity protection services. No agent has been or likely will be notified of specific applicants (if any) who were affected.

PHI Breach by Individual Applicant, Attorneys

Anthem Blue Cross recently learned of a situation in which a small number of individuals manipulated the web address within the website we use to allow people to track the status of their Individual insurance applications. Through this manipulation, some of these individuals gained unauthorized access to certain private information.

The vast majority of the manipulation and the resulting unauthorized access occurred at the hands of certain attorneys, who were representing an applicant. We believe that this manipulation was conducted to support a class action lawsuit against Anthem Blue Cross or its parent company - over the very breach they were committing.

The ability to manipulate the web address (URL) was available for a relatively short period of time following an upgrade to the system. After the upgrade was completed, a third party vendor validated that all security measures were in place, when in fact they were not. As soon as the situation was discovered, we made the necessary security changes to prevent it from happening again.

Anthem has worked since discovery of this matter to analyze the data in an effort to identify all individuals whose information may have been impacted and prepared to communicate directly to affected members and applicants as soon as possible.

We have received no indication that any information has been used in a way that is detrimental to the applicant; however, out of an abundance of caution, all appropriate applicants will receive a detailed notification from Anthem explaining what happened, and will be offered identity protection services for one year at no cost.

Note: This does not impact Group, Senior or State-Sponsored Business.

My ZimbioMy Ping in TotalPing.com

Blog Archive

Followers