Privacy Digest

News that can impact your privacy.
Login/Register
What is OpenID?
  • Log in using OpenID
  • Cancel OpenID login
  • Create new account
  • Request new password
Home Blogs MacRonin's blog
    • FAQ
    • Wishlists
    • Contact
    • Categories/RSS

Bookmark Us

Bookmark Privacy Digest 
Bookmark This Page 

Syndicate

Syndicate content
more

Advertisements

Tracking System
GPS Tracking
Tracking System
Private Detectives
Quality Security Services in California
Fleet Management
Hosting

Popular content

Last viewed:

  • Sneaky Microsoft plug-in puts Firefox users at risk
  • Smart tags to reveal where our trash ends up - environment
  • Feds’ Smart Grid Race Leaves Cybersecurity in the Dust
  • Comcast Unveils Its New Traffic Management Architecture
  • Viacom, YouTube, and the Dangerous Assembly of Facts
  • Google Superbowl Ad Explains The Need for Search Privacy
  • Pirate Bay 2.0: Pay Pirates to Become Consumers

tags in Topics

Activists Alert Companies Congress Copyright Court (US) Databases Data Mining Editorial EFF Entertainment Exploits Fourth Amendment Government Hmmm ID Infrastructure Law Enforcement Laws Politics Privacy Remember Reports Rights Security Software Spin Zone Surveillance Telecommunications Tracking
more tags

View blog authority
Congressional Research
Broadcast Flag

Health Insurer Loses 1.5 Million Patient Records

Submitted by MacRonin on November 23, 2009 - 5:21pm
  • Companies
  • Connecticut
  • Data Breach
  • Databases
  • HIPAA
  • Hmmm
  • ID
  • Person Career
  • Privacy
  • Quotation
  • Remember
  • Richard Blumenthal
  • Security
  • Spin Zone

Health Insurer Loses 1.5 Million Patient Records: Via Threat Level.

A health insurer lost 1.5 million patient records last May but waited six months to disclose the incident.

The data, which was stored on a portable disk drive that disappeared from the insurer’s office, was unencrypted and included patient Social Security numbers, bank account numbers and health data, according to the Hartford Courant. The disk also contained personal information on at least 5,000 physicians.

Health Net discovered the loss in May but never informed patients, law enforcement or government entities, despite data breach laws in some states that require data spillers to notify victims and state officials when residents are affected by a breach. The insurer finally sent a letter to Connecticut’s attorney general and the state’s Department of Insurance this week.

Health Net claimed it took six months to determine what data was on the missing disk. It said that data on the disk was compressed and stored in an image format that required special software to view, which was available only to HealthNet.

“Another day, another data breach,” said Connecticut Attorney General Richard Blumenthal in a statement. “But companies still don’t get it: Personal information is like cash and should be guarded with equal care.”

Blumenthal vowed to pursue an investigation and legal action against the insurer. About 450,000 of the patients affected by the data loss are residents of Connecticut, which has a breach notification law. Patients in Arizona, New Jersey and New York were also affected.

“My investigation will seek to establish what happened and why the company kept its customers and the state in the dark for so long,” Blumenthal told the Hartford Business Journal. “The company’s failure to safeguard such sensitive information and inform consumers of its loss — leaving them naked to identity theft — may have violated state and federal laws. I will vigorously and aggressively seek damages, penalties and other appropriate remedies, if warranted.”

On a separate note, a second health insurer mailed 80,000 postcards to Medicare recipients last week that listed the patient’s Social Security number on the front of the card beneath the patient’s name. Universal American Action Network, a subsidiary of Universal American Insurance, blamed the company that printed the cards for the error but didn’t explain why the company had the patient Social Security numbers in the first place.

The data leak affected patients enrolled in the Medicate Advantage plan, which uses a patient’s Social Security number as his Medicare account number.

Photo: /Flickr

Read Original Article:(Via Threat Level.)

Bookmark/Search this post with:
  • Twitter Twitter
  • Digg Digg
  • StumbleUpon StumbleUpon
  • Technorati Technorati
  • del.icio.us del.icio.us
  • Facebook Facebook
  • Furl Furl
  • LinkedIn LinkedIn
  • Yahoo Yahoo
  • MacRonin's blog
  • Add new comment

Recent blog posts

  • EFF Asks Court to Suppress Evidence Illegally Gathered From Password-Protected Phone
  • Google Superbowl Ad Explains The Need for Search Privacy
  • EFF Fights for Cell Phone Users' Privacy in Thursday Hearing
  • Identifying John Doe: It might be easier than you think
  • ShmooCon: Inside FarmVille's sinister underbelly
  • More Details on the Chinese Attack Against Google (Schneier)
  • The top 5 mistakes of privacy awareness programs
  • ShmooCon: P2P snoopers know what's in your wallet
  • Can you trust Chinese computer equipment?
  • Authors Guild: ‘To RIAA or Not to RIAA’
more

Performancing Metrics

Compilation © Copyright 1997-2010 Paul Hardwick, with Web Hosting provided by MacRonin.com.