Newspaper: Medical information of 75,000 Empire Blue Cross members lost

Share this article:

Empire Blue Cross and Blue Shield, a division of WellPoint serving New York State, has begun notifying 75,000 members that a compact disc holding their personal and medical information has been lost, according to published reports.

The personal data was stored on an unencrypted CD that had been sent to Magellan Behavioral Services, a firm that facilitates mental health and substance abuse treatments for insurance providers, according to a report today in the New York Times.

Lost data included names, Social Security numbers, health plan ID numbers and descriptions of medical services rendered since 2003, according to the Times’ report.

Representatives from Magellan and Empire could not be immediately reached for comment today.

Paul Stephens, policy analyst at the Privacy Rights Clearinghouse, told SCMagazine.com today that, along with the compromise of sensitive medical information, victims should be concerned about the financial risks such as identity theft.

"The fact that Social Security numbers are involved means there is a financial risk for those individuals because there would be sufficient information for anyone to open up a credit card or bank account or a wireless service account," he said. "People tend to be very private about health-care issues, and when you bring up health care, there are other issues to think about, like HIPAA (the Health Insurance Portability and Accountability Act). One thing to think about is, was there anything leading up to this that might’ve been a potential HIPAA breach. That’s unlikely, but it’s possible."

According to research released this month from the IT Policy Compliance Group, 75 percent of all data breaches were caused by human error.

Click here to email Online Editor Frank Washkuch.

Share this article:

Sign up to our newsletters

More in News

Brazilian president signs internet 'Bill of Rights' into law

Brazilian president signs internet 'Bill of Rights' into ...

President Dilma Rousseff signed the legislation on Wednesday at the NetMundial conference in Sao Paulo.

Android trojan sends premium SMS messages, targets U.S. users for first time

Android trojan sends premium SMS messages, targets U.S. ...

An SMS trojan for Android, known as FakeInst, has been observed sending premium SMS messages to users all over the world, including, for the first time, the United States.

Report: DDoS up in Q4 2013, vulnerability scanners leveraged to exploit sites

Report: DDoS up in Q4 2013, vulnerability scanners ...

Researchers observed 346 DDoS attacks in the final quarter of 2013 and attackers used Vega and Skipfish vulnerability scanners to exploit web flaws at financial companies.