Email contains personal data on thousands of insurance agents

Share this article:
Agents with a state online health insurance exchange in Minnesota may have had data compromised.
Agents with a state online health insurance exchange in Minnesota may have had data compromised.

Thousands of agents with state online health insurance exchange MNsure in Minnesota may have had personal data compromised when an employee inadvertently sent out an email attachment that contained the information.

How many victims? More than 2,400 insurance agents.

What type of personal information? Names, business addresses, license numbers and Social Security numbers, among other identifying information.

What happened? A MNsure employee inadvertently attached an Excel spreadsheet that contained the personal information to an email, which was then sent out to an Apple Valley insurance broker's office.

What was the response? Upon realizing the error, the MNsure employee contacted the Apple Valley insurance broker and asked him to delete the email with the file. MNsure officials followed up with more detailed instructions shortly after. All affected agents are being notified of the incident. An investigation is ongoing.

Details: The email and attachment was sent to the broker on Thursday.

Quote: “MNsure takes this incident extremely seriously,” a MNsure official said in a statement. “While it appears that this incident was accidental, MNsure will conduct a thorough investigation to fully understand the nature of the incident. MNsure has a data privacy policy in place, and this employee's action was a violation of this policy.”

Jim Koester, the recipient of the file, said that “the gorilla in the room is that they sent me something that's not even encrypted. It's unsecured, on an Excel spreadsheet – which is using outdated technology to transfer that information in the first place. They've got to realize they have a huge problem.”

Source:, Star Tribune, “Errant e-mail creates security breach at MNsure,” Sept. 12, 2013.

Share this article:

Sign up to our newsletters


More in The Data Breach Blog

Another breach involving Onsite Health Diagnostics, Kansas City hospital impacted

Children's Mercy Hospital is notifying more than 4,000 individuals that their information may have been compromised after an Onsite Health Diagnostics system was breached.

Vitamin seller website attacked, payment cards and other info compromised

Credit and debit cards, as well as other information, may have been compromised by an attacker who gained access to computer system.

Subcontractor breach impacts more than 60K Tennessee workers

An unknown attacker hacked into the computer system of a subcontractor and accessed personal information on more than 60,000 Tennessee workers.