Anthem Data Breach Expected to Cost Over $100 Million
A HIPAA breach carries a huge financial penalty and one the scale of that which recently affected Anthem Inc., is expected to result in costs of many tens of millions of dollars. Anthem holds an insurance policy from the American International Group to protect against cybercrime and data exposures, and is covered for losses up to $100 million. Even this sizeable amount may be exhausted with the latest data breach. The total cost, which is unlikely to be known for many months, may exceed the 100M barrier once the cost of issuing breach notifications, paying OCR penalties, implementing new security measures and fighting lawsuits are factored in. Further costs must also be covered to mitigate any damage caused such as providing credit monitoring services to victims free of charge. Anthem originally offered a year of credit monitoring services but has since extended this to two year. If 80 million individuals have been affected, damage mitigation costs alone will take up a sizeable chunk of the insurance payment. The OCR has already announced that it is looking into the breach as a...
Details Emerge of Anthem HIPAA Breach
The colossal security breach at Anthem Inc, which exposed the Social Security numbers and personal details of 78.8 million plan members, is understood to have involved data from as early as 2004. The investigations are ongoing and it is currently not known exactly how many of its members have been affected. A recent U.S. News and World Report indicates that hackers previously attempted to access the system as early as December 10, 2014. Anthem’s announcement of the breach indicated that January 27, 2015 was the first occasion that access had been gained. Anthem Spokeswoman, Kristin Binns, did not confirm the exact date of the breach, but later announced that “The hackers succeeded in penetrating the system and stealing customer data sometime after Dec. 10 and before Jan. 27”. Forensic investigators have discovered a number of network access attempts that all carry the same hallmarks, and it would appear that numerous unauthorized data access queries were made during this period using the login credentials of five Anthem Technical workers. The company’s security system appears to...
Federal Officials to Explore HIPAA Rules on Data Encryption
On Friday last week, a day after Anthem Inc., announced the largest ever reported HIPAA breach, the Senate Health, Education, Labor and Pensions committee announced that the healthcare IT security is to be addressed and that it will “take up the matter as part of a bipartisan review of health information security”. The AP reports Jim Jeffries, spokesman for chairman Lamar Alexander, R-Tenn, as saying “We will consider whether there are ways to strengthen current protections.” Last year saw major data breaches at Sony Pictures and Target which exposed highly sensitive information about employees and customers, while the healthcare industry was hit with a number of breaches including the successful hacking of Community Health Systems in April and June, in which 4.5 million patient records were exposed. The latest incident is on an unprecedented scale in healthcare, having affected up to 80 million individuals. The latest breach confirms the FBIs warning of increased attacks on healthcare organizations. Hackers are targeting organizations for the data they hold and the...
Burglary Causes 45,030-Patient HIPAA Breach at Aspire Indiana
Aspire Indiana has announced that the PHI of 45,030 individuals had been obtained by thieves in a Nov 7, burglary of its administrative offices. The perpetrator(s) stole a number of laptop computers containing unencrypted PHI, including 1,548 identifiable Social Security numbers. This incident exposed more Protected Health Records than the December’s Sony Pictures Entertainment Health and Welfare Benefits Plan breach and January’s UMass Memorial Medical Group HIPAA breach combined. Aspire Indiana, Inc., is a private behavioral and mental health not-for-profit organization with administrative offices in Noblesville, Indiana. It was these offices that were burglarized according to the notice and the crime has has been reported to law enforcement which is conducting an investigation. It is not clear whether the thieves broke into the offices with the intention of stealing medical records. As soon as the theft of the PHI was discovered, the company immediately embarked on a process of damage mitigation. It commissioned a forensic analysis to determine exactly what data was stored on...
HIPAA Breach Report: November 2014
November 2014 HIPAA Breach Summary: Under the Health Insurance Portability and Accountability Act, all covered entities – including their Business Associates – are required to report data breaches affecting more than 500 individuals to the Office for Civil Rights. The report must be made via the HHS’ breach notification portal. Covered entities have up to 60 days to report breaches from the data of discovery This report contains a summary of the breaches reported to the OCR during the month of November, 2014. Major HIPAA Breaches in November 2014 Although relatively few data breaches were reported as having occurred in November, a high proportion involved the disclosure of tens of thousands of patient records. The largest HIPAA breaches involved the theft of data and network server incidents. The Central Dermatology Center, P.A. (NC), reported a data breach in which 76,258 health records were exposed after malware was identified on its network, although it is not clear if any information was viewed or obtained. Visionworks Inc. (TX) announced a 74,944-record HIPAA breach...



