10 Million Affected by Sophisticated Cyberattack

McGuireWoods LLP
Contact

The latest major health insurance data breach of 2015 reported by Excellus BlueCross BlueShield is considered one of the top 20 worst reported breaches of a healthcare organization.  The attack affected about 7 million Excellus members and 3.5 million members of its subsidiary, Lifetime Healthcare Cos. and potentially exposed individual names, addresses, birth dates, Social Security numbers, member identification numbers, financial account information, claims data and clinical information, which would likely include medical data.

Significantly, the incident occurred two years ago but was only discovered in August. Specifically in response to previous security breaches at other insurance companies, Excellus hired a leading cybersecurity firm to conduct a forensic assessment of its IT systems.  That investigation revealed that hackers initially gained access to highly personal information on December 23, 2013. This breach is alarming because Excellus BlueCross BlueShield’s considerable efforts to safeguard the privacy of personal information did not prevent the breach.  According to Excellus, the company encrypted the sensitive information, but the encryption method did not prevent hackers from accessing the information.  Hackers were able to circumvent the company’s encryption by accessing decryption keys available to administrators. The Excellus breach was discovered because the company was proactive in finding and addressing data privacy and security vulnerabilities.  This discovery raises the question, “What breaches have occurred in other organizations that have not been discovered simply because they are not looking?”  It is another reminder for organizations to be constantly vigilant and to scrutinize systems for vulnerabilities.   Organizations that own, license or maintain personal information should implement and follow stringent security defensive measures, consider hiring third party forensic experts, and limit liability with appropriate cyber insurance.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© McGuireWoods LLP | Attorney Advertising

Written by:

McGuireWoods LLP
Contact
more
less

McGuireWoods LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide