PHI Breach

PHI Breach by Individual Applicant, Attorneys

Blue Cross and Blue Shield of Georgia (BCBSGa) recently learned of a situation in which a small number of individuals manipulated the web address within the website we use to allow people to track the status of their Individual insurance applications. Through this manipulation, some of these individuals gained unauthorized access to certain private information.

The vast majority of the manipulation and the resulting unauthorized access occurred at the hands of certain attorneys, who were representing an applicant.  We believe that this manipulation was conducted to support a class action lawsuit against Blue Cross and Blue Shield of Georgia or its parent company – over the very breach they were committing.

The ability to manipulate the web address (URL) was available for a relatively short period of time following an upgrade to the system. After the upgrade was completed, a third party vendor validated that all security measures were in place, when in fact they were not.  As soon as the situation was discovered, we made the necessary security changes to prevent it from happening again.

BCBSGa has worked since discovery of this matter to analyze the data in an effort to identify all individuals whose information may have been impacted and prepared to communicate directly to affected members and applicants as soon as possible.

We have received no indication that any information has been used in a way that is detrimental to the applicant; however, out of an abundance of caution, all appropriate applicants will receive a detailed notification from BCBSGa explaining what happened, and will be offered identity protection services for one year at no cost.

Note: This does not impact Group, Senior or State-Sponsored Business.

Download Article

[Post to Twitter] Tweet This Post 

© 2008-2012 Julie Ryan All Rights Reserved -- Copyright notice by Blog Copyright

Tweet This Post links powered by Tweet This v1.3.9, a WordPress plugin for Twitter.

wordpress visitor