Centene announces search for missing hard drives containing PHI of 950,000 individuals

Robinson+Cole Data Privacy + Security Insider
Contact

Centene Corporation, a health insurer headquartered in St. Louis, announced on January 25, in a press release that it is undertaking an, “ongoing comprehensive internal search for six hard drives that are unaccounted for in its inventory of information technology (IT) assets.”

The press release states that the hard drives contained the names, addresses, dates of birth, Social Security numbers, member ID numbers, and health information of members who received laboratory services between 2009 and 2015.

Centene is notifying the affected individuals of the loss of the hard drives and is offering free credit and healthcare monitoring. It stated that it will continue to search for the hard drives, but they are unaccounted for at this time.

Two points: health care entities may want to consider whether full Social Security numbers should continue to be included in all of the data it receives and stores on an individual—do you really need the entire SSN on that hard drive; and second, full encryption of data at rest. If this information had been encrypted, it could not be viewed, stolen or used.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Robinson+Cole Data Privacy + Security Insider | Attorney Advertising

Written by:

Robinson+Cole Data Privacy + Security Insider
Contact
more
less

Robinson+Cole Data Privacy + Security Insider on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide