Several times in November 2018, Colbi Trent Defiore, a then seasonal employee for a Virginia-based tech company that operates contact centers for Medicare enrollment for CMS, inappropriately accessed personal identifying information of more than 8,000 individuals in the Healthcare.gov database, according to a Dec. 10 news release from the U.S. Attorney’s Office for the Eastern District of Louisiana.
Mr. Defiore worked at the company’s Bogalusa, La.-based center, where he illegally searched the Healthcare.gov database, copied the results of his searches and emailed them to himself. He then used the personal information of at least five consumers to apply fraudulently for at least six credit cards, loans and lines of credit, according to the U.S. Justice Department.
“In total, [Mr. Defiore’s] conduct caused reasonably foreseeable loss to the companies that operated the call center, including costs associated with responding to the offense, conducting a damage assessment, responding to and remediating damage, contacting consumers who were potential victims, and providing theft protection services for consumer-victims, in the amount of $587,000,” the U.S. Justice Department’s release states.
More articles on cybersecurity:
HHS proposes HIPAA changes: 7 things to know
Ransomware groups becoming more sophisticated: 3 details
Colorado hospital reports data breach after surveyor loses storage device: 3 notes
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.