• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

Health Insurer Fined $5.1m Over Data Breach

You are here: Home / General Cyber Security News / Health Insurer Fined $5.1m Over Data Breach

An American wellness insurer has agreed to fork out $5.1m to the Office environment for Civil Rights (OCR) at the US Department of Overall health and Human Solutions (HHS) to settle likely violations of the Well being Insurance Portability and Accountability Act (HIPAA) Privacy and Security Regulations.

The agreement entered into by Excellus Well being Plan, Inc. relates to a data breach that lasted 17 months and influenced about 9.3 million individuals. 

✔ Approved Seller by TheCyberSecurity.News From Our Partners
Acronis True Image 2021

Protect and backup your data using Acronis True Image. Acronis is made in Germany and is a leading brand in IT back up and secirity for years. Acronis True Image take secure and enxrypted backups from your Wdindows and macOS. With Acronis True image you will never be worried about Ransomware attacks and virus infections.

Get Acronis with 50% discount from our partner: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


Excellus is a New York–based health solutions company that gives wellbeing insurance coverage protection to more than 1.5 million folks in upstate and western New York.

A breach report submitted by Excellus on September 9, 2015, said that cyber-attackers had acquired unauthorized obtain to the company’s data technology programs.  

The breach started on or prior to December 23, 2013, and dragged on until eventually May perhaps 11, 2015. Right after gaining entry to the company’s techniques, destructive hackers set up malware and performed reconnaissance functions that in the end resulted in the disclosure of shielded overall health information and facts (PHI) of much more than 9.3 million individuals.

Data exposed in the attack involved names, addresses, dates of beginning, email addresses, Social Security quantities, lender account details, health plan promises, and medical treatment method facts.

Plans impacted by the breach have been BlueCard Customers BlueCross BlueShield of Central New York BlueCross and BlueShield of the Rochester space BlueCross BlueShield of Utica-Watertown and Excellus BlueCross BlueShield.

OCR’s investigation into the security incident discovered likely violations of the HIPAA rules, which includes failures to implement risk administration, details procedure action review, and access controls and failure to conduct an enterprise-wide risk evaluation.

“Hacking continues to be the greatest threat to the privacy and security of individuals’ health data. In this circumstance, a wellbeing plan did not cease hackers from roaming within its well being history procedure undetected for more than a year, which endangered the privacy of tens of millions of its beneficiaries,” explained OCR director Roger Severino. 

“We know that the most hazardous hackers are innovative, individual, and persistent.  Health care entities will need to stage up their sport to secure the privacy of people’s wellbeing information from this growing danger.”

In addition to spending a sizable monetary settlement, Excellus has agreed to undertake a corrective action plan that features two several years of checking.


Some parts of this write-up are sourced from:
www.infosecurity-magazine.com

Previous Post: «Cyber Security News EEMA Appoints Digital Identity Expert to Board of Management

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Recent Posts

  • Health Insurer Fined $5.1m Over Data Breach
  • EEMA Appoints Digital Identity Expert to Board of Management
  • Medical Device Security: Diagnosis Critical
  • MoD Experiences 18% Growth in Personal Data Loss Incidents
  • Thales and TT Electronics Partner to Enable OT Cybersecurity Initiatives and Research
  • Joker’s Stash Carding Site to Close in February
  • Environmental Regulator Suffers Ransomware Blow
  • WhatsApp delays controversial privacy update for businesses
  • IT retailer faces €10.4m GDPR fine for employee surveillance
  • Leaked #COVID19 Vaccine Data “Manipulated” to Mislead Public

Copyright © TheCyberSecurity.News, All Rights Reserved.