Excellus BCBS pays $5.1M to settle data breach affecting 9.3 million people

Excellus BlueCross BlueShield agreed to pay the Office for Civil Rights $5.1 million to settle potential HIPAA violations related to a data breach, HHS said Jan. 15. 

Advertisement

In September 2015, Excellus filed a breach report that said cyberattackers gained access to its IT systems. The breach began in December 2013 and ended in May 2015, Excellus said.

More than 9.3 million people were affected by the breach, according to HHS. The hackers installed malware into Excellus’ IT system, which led to the disclosure of people’s Social Security numbers, bank account information and clinical treatment information, among other personal data.

An investigation from the OCR found Excellus may have violated HIPAA by failing to conduct a risk analysis and IT system review.

In addition to the settlement, the insurer also agreed to implement a corrective action plan, which includes two years of monitoring. 

Read more here.

More articles on payers:
UnitedHealthcare suspends some prior authorization rules for hospitals
BCBS Association to suspend donations to lawmakers who disputed Electoral College results
Cigna to suspend donations to lawmakers who ‘supported violence’ at Capitol

Advertisement

Next Up in Uncategorized

  • Sacroiliac joint fusion technology is advancing, and the data shows it’s efficacy across different medtech companies. Five notes: 1. Tenon…

  • Robert Mach was appointed CEO of Schoolcraft Memorial Hospital in Manistique, Mich., effective Aug. 15. Mr. Mach brings a wealth…

  • Nashville, Tenn.-based HCA Healthcare, the largest health system in the country, is seeking finance chiefs at four of its hospitals. …

Advertisement

Comments are closed.