JAN 15, 2010 5:06am ET

Related Links

New Product News – May 17, 2013
May 16, 2013
8 Risks Inherent to All Organizations
May 14, 2013
Second World Risk Day Takes a Project-Minded Path
May 9, 2013

Web Seminars

Data Protection in the Cloud: What You Need to Know About Security and Compliance—Right Now
Available On Demand

Tenn. Blues Breach Affects 500,000

Print
Reprints
Email

BlueCross and BlueShield of Tennessee has announced it has so far notified more than 157,000 members of the theft of identifiable data in early October that affected an estimated 500,000 members. The Chattanooga, Tenn.-based insurer announced the theft within days of its occurance. It started notifying members in early December as evidence that their information was on stolen files surfaced during an investigation that continues.

In October, 57 hard drives containing audio and video files were stolen from a leased facility that previously housed a call center and was in a transition stage with some employees still working at the facility. The files related to coordination of care and eligibility phone calls from providers and members. The video files were images from computer screens of customer service representatives and the audio files were recorded telephone conversations. The stolen material included an estimated 1.3 million audio files and 300,000 video files.

The files contained demographic information and BlueCross ID numbers. They also contained diagnostic information and Social Security numbers for many of the affected members. The files were encoded, which is a process of converting data by use of a code to make it unreadable, but not encrypted, which changes plain text into ciphertext, or characters, using algorithms and a key.

The plan hired New York security firm Kroll Inc. to review backup files and identify affected members, conduct forensic data matching to determine the data at risk for each member, and to assess BCBS of Tennessee's systemwide security. The plan "has taken several actions to strengthen these protocols," the company said in a Jan. 13 statement updating its progress. Among the changes is a requirement now that all data resides in properties that BCBS of Tennessee owns, according to a spokesperson.

The theft occurred on Oct. 2 and the plan learned about it on Oct. 5. Work to identify and match data began on Oct. 7. The plan and Kroll completed an audit of back-up files on Jan. 4 with analysis of the data continuing. Notification letters to affected members started on Dec. 7.

As of Jan. 7, the insurer has identified 220,000 members at highest risk and has notified more than 157,000. These members had their Social Security number among the data that was stolen. The plan remains in the process of identifying and notifying additional members at lower risk because their Social Security numbers were not among the data. All affected members will receive free credit monitoring and identity theft protection services for one year, with enhanced services for those with compromised Social Security numbers.

To date, the insurer has found no evidence that any data has been accessed and used. More information is available at bcbst.com.

This article can also be found at HealthDataManagement.com.

Joseph Goedert is news editor at Health Data Management.

Filed under:

Advertisement

Comments (0)

Be the first to comment on this post using the section below.

Add Your Comments:
You must be registered to post a comment.
Not Registered?
You must be registered to post a comment. Click here to register.
Already registered? Log in here
Please note you must now log in with your email address and password.

Where do young IT professionals (30 and under) obtain information to aid with daily role responsibilities and career development?

Trade publication websites 14%
Social media 23%
Vendor websites 4%
Vendor/community forums 7%
Newsletters 1%
Trade conferences/meetups 2%
RSS feeds 6%
Web search 44%

 

Twitter
Facebook
LinkedIn
Login  |  My Account  |  White Papers  |  Web Seminars  |  Events |  Newsletters |  eBooks
FOLLOW US
Please note you must now log in with your email address and password.