Anthem Blue Cross breach notification [pdf]
oag.ca.gov
oag.ca.gov
> We:
> • Looked into what caused this issue.
> • Are taking steps to reduce the risk of this happening again.
> • Temporarily shut down the portal account
So, they cheap out on security, cause MY PII to be leaked (enough for identity theft) and all they do is shut my own access out?
No details on "Are taking steps to reduce the risk of this happening again" because I bet all they did was shut off this one hole rather than revamp their security.
For the record, this isn't even the first Anthem BC breach: In 2015, they had a breach so large that it has its own Wikipedia page. https://en.wikipedia.org/wiki/Anthem_medical_data_breach
In 2020, Anthem had net income of $4.57 billion. If they are fined at/settled for the same level as the 2015 breach (~$150M), then their incentive is to continue playing fast and loose with data rather than invest in sane security.
Bob I want you to find me the best(cheapest) security contractor you can find.
Few moments later......Sorry, we had another breach, we had one of the best security experts in the world look over our systems and made appropriate changes. We increased our security budget from $5 to $5.01.
Have you checked out our corporate events? Those are really fun and we really go all out for our employees.
https://www.fiercehealthcare.com/privacy-security/anthem-agr...
f) Attorney Fees and Costs. Plaintiffs will also separately petition for an award of attorneys’ fees and reimbursement of litigation expenses from the Settlement Fund. Plaintiffs will not seek more than 33% of the Settlement Fund ($37,950,000) for attorney fees, which as counsel pledged at the onset of the litigation will amount to considerably less than 1.75 times their reasonable lodestar, already reduced in the exercise of billing judgment. Cervantez Decl. ¶ 18. They will also will not seek more than $3,000,000 in expense reimbursements, and will support their application with detailed lodestar information and an accounting of their expenses. Id. ¶ 19. Defendants have agreed not to oppose Plaintiffs’ application
https://s3.amazonaws.com/assets.fiercemarkets.net/public/004...
Source: Equifax 2017.
No consequences, the trend will continue. Consider all of your information compromised, always.
It's completely ridiculous. There's zero consequences for bad security. All companies need to do is report the breach to the government, buy "credit monitoring" for the victims which costs pennies, and deal with half a day of bad press on Twitter. Meanwhile, consumers have to deal with identity theft consequences, which in a court of law, is nearly impossible to tie back to a specific incident.
Until governments impose serious fines, even to mom and pop businesses scaled up to massive corporations, this will not change.
People already use GoodRx discount cards at pharmacies.
Good luck getting your insurance company that pays $100k to senior engineers to do that.
>$100k to senior engineers
Could be half that and no technical screening whatsoever.
Outsourcing frequently means outsourcing to people in the US who are paid enough less to be a logical option.
On the EU side, we have smart chip national ID cards that are being adopted EU-wide.
In Croatia, you can use those smart chip national ID cards for governmental affairs with a USB smart chip reader (for authentication) on the e-citizens portal.
Especially with the right systems far more people can be harmed than by a building collapse :p
>Until governments impose serious fines
Or maybe change the language? It's not possible to steal an identity; it's a fiction that is convenient for corporations handling personal information in ways that cost society.
I knew of 5 different ways I could have exfiltrated the entire PHI of every member without them having any knowledge of it and the SecOps manager just ignored it because they were “to busy”. Throw in archaic security requirements passed down from the BCBSA that do nothing to actually improve security but generally make it harder to work and you have a recipe for disaster.
The former CTO of Blue Shield of California told me back in 2012 (re tech talent):
> “We have the Ds and the Fs of the industry. I mean, who would want to work for a payor (insurance co) in SF?”
(Quoted to the best of my memory… But the first sentence is pretty much verbatim)
I 100% agree.
I also wonder what the solution could be though… Especially for geographies that have lots of more interesting companies to work for.
We could sit here and say “they could pay market rates“ (or even, “they could pay shiploads of cash, benefits, etc”) but, from the little data I gathered from the CTO and others, some of the difficulties are 1. that the problems they have are generally not very interesting because… 2. their risk tolerance is -1000 since 3. innovation & change is seen as - and can pose a very material - risk, and 4. They are a slow and stodgy companies mired in regulations and guided by legal teams* (Also means offering stock/upside underperforms tech companies by a mile)
I’m trying to imagine a scenario where (as a person with plenty of options) I would be interested in joining the health insurance company for longer than a year or two…
Even if they gave me a massive salary, a gorgeous office, a robust team, they would still have massive challenges to give impactful problems to work on without getting mired in internal legal battles and committee reviews.
Having seen several insurers from the inside most of them would need massive internal cultural changes just to hire a handful of A-players and retain them for any reasonable length of time (make that triple true with the pandemic popularizing remote work)*
* A quote from the #3 person at Regence who I worked with: “I love this!” (Re a startup product.) “How do we get it around legal and through procurement?”
Even someone who controlled 1/3 of all revenue made by the business still could be stymied by legal & procurement.
* There is one shining star I could point to… Regence BlueCross BlueShield of the Pacific Northwest. They are owned by a parent company, Cambia, which also has an accelerator, venture arm, and an innovation lab if I remember correctly.
They have solved some of these issues by investing in innovators such as spotlight health to help them solve their business needs. However, I don’t believe (though I have no data) they had a robust internal security team for all the reasons listed above.
(I haven’t had any contact or affiliation with him in about eight years.)
Source: I work in the industry.
I contacted the doctor's office, and they sent me back the plaintext password.
That's when I knew.
I didn't read them or investigate to see whether it was just my own that were available, but I'm pretty sure it was a mistake in setting permissions.
Some time later the whole portal disappeared, except for a bill pay page. Also the provider suddenly quit with no warning; I don't recall the sequencing.
Nobody ever sent me a letter fessing up to anything.
Yes, I'm aware and I have requested my records in the past. I can even spell HIPAA, unlike a lot of people.
This is irrelevant to my anecdote about the screwed up portal, since I would be aware and have mentioned it if I made such a request, which I did not.
>What would they need to "fess up" about?
Like I said, I didn't investigate to find out the full story, because we all know what happens if you "hack" a broken system.
I'm not following you to the conclusion that it must be broken because it gave you access to your own records.
No.
Are you sure you aren't just expecting to have to request it, and are being surprised by the fact that you don't?
I have a primary care doctor whose portal has the sort of thing you're referring to. That's different.
- Company doesn't follow security practices and leaks data
- Feds get notified if it's a big enough breach. Btw, this is from the good will of the company
- Data Brokers...erm, Credit Agencies, then monitor for the data...i guess the insurance company sent it to them too, so they know what to look for?
- I don't know who pays for this (originating company, tax payers, etc)
- Credit Agencies now get to monitor you. Watch what you do under the guise of protecting you. While still building your credit score.
- Hopefully the info leaked and being used is accurate. If not, the Credit Agency has no obligation to fix it unless you say so and even then it can take a long time to remedy.
This just seems fucked.
Ha, now that I think of it, they probably had signs saying no recording and/or turn off your phone, so I may not have even been permitted to record what they said.
The root cause is a clause in Federal law[1] that precludes an individual from holding a creditor or credit bureau liable for inaccurate information regarding that individual. If we were able to sue the creditor and credit bureau because they engaged in libel, then identity theft would no longer be a thing because there would be incentive for banks and other creditors to actually verify the identity of the individual before issuing credit.
I think instead what we need to do is:
A) have “egregious” problem multipliers that stack. Using outdated cryptographic designs? 10x damages multiplier. Using software with known vulnerabilities that was part of the breach? 100x multiplier. Not encrypting data at rest? 1000x multiplier. Etc etc.
B) develop a standard whereby my PII is not allowed to be stored and you only get access to it at time of use (this would also largely solve the problem of the shadow data marketplace).
Even with all that, you could have a security breach where someone has a Trojan spying on all traffic live on the system and stealing that PII once it’s decrypted. So the problem isn’t solvable but maybe these kinds of steps might raise the bar.
They were sued and settled in 2017 [2].
[1] https://resources.infosecinstitute.com/topic/the-breach-of-a... [2] https://www.businessinsurance.com/article/00010101/NEWS06/91...
Uh, why do they think someone would illegally access information? Just for fun?
Direct patient contacts are a vanishingly small percentage of records requests for a doctor. Doctors could likely handle those via phone, but it doesn't solve the issue of needing an EMR.
There's some additional information here: https://www.securitymetrics.com/static/resources/orange/HIPA...
Source: have worked in a medical office
Why is this needed? If my bank erroneously decides to let somebody else transfer funds out of my account, or lets somebody else establish a debt in my name, then that's just a bank error. Is my bank not liable for that?
We have no reason to believe that someone will misuse your information because of what happened
This information would be sufficient to pass identity checks for phone calls at most non-finance companies I've interacted with, including all healthcare providers.On a somewhat related note: I don't think Aetna is too far behind. Their website is just as awful as Anthem and as a software dev myself, I know that if you don't put care into your consumer-facing products, your security is probably really poor.
Yeah, ok. They literally sent victims to a DATA BROKER to "protect" them. The very same people who would buy up that leaked data that came the "hack." What fucking world do we live in??
Edit: ...
https://oag.ca.gov/system/files/CA%20HITECH%20DTN%201020172....
I found that via the whole list: https://oag.ca.gov/privacy/databreach/list
I recently was admitted to an American hospital due to sepsis for an extended period of time, when I was visiting family for a few months (fortunately I am insured in the United States even while abroad).
The hospital required the nurses to administer IV meds in a very peculiar way.
One week into my hospital stay, they started a new programme administering IV meds with code executed from the Electronic Health Record (Epic) to the pump. The pump would start as soon as the barcodes for the IV meds were scanned. The infusion rates were programmed into the electronic health record so the nurses didn’t have to manually program the pump.
2023 individuals affected.
> The requested page "/system/files/ca%20hitech%20dtn%201020172.pdf" could not be found.
EDIT: Now I'm not, and I can load the PDF. Not sure why.
We changed our password from 1234 to OhMFGwerefucked1234