Medical-Data Breach Said To Be Major - Insurance News | InsuranceNewsNet

InsuranceNewsNet — Your Industry. One Source.™

Sign in
  • Subscribe
  • About
  • Advertise
  • Contact
Home
Topics
    • Advisor News
    • Annuity Index
    • Annuity News
    • Companies
    • Earnings
    • Fiduciary
    • From the Field: Expert Insights
    • Health/Employee Benefits
    • Insurance & Financial Fraud
    • INN Magazine
    • Insiders Only
    • Life Insurance News
    • Newswires
    • Property and Casualty
    • Regulation News
    • Sponsored Articles
    • Washington Wire
    • Videos
    • ———
    • About
    • Advertise
    • Contact
    • Editorial Staff
    • Newsletters
  • Exclusives
  • NewsWires
  • Magazine
  • Newsletters
Sign in or register to be an INNsider.
  • AdvisorNews
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Exclusives
  • INN Magazine
  • Insurtech
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Video
  • Washington Wire
  • Life Insurance
  • Annuities
  • Advisor
  • Health/Benefits
  • Property & Casualty
  • Insurtech
  • About
  • Advertise
  • Contact
  • Editorial Staff

Get Social

  • Facebook
  • X
  • LinkedIn
Get our newsletter
Order Prints
October 21, 2010
Share
Share
Tweet
Email

Medical-Data Breach Said To Be Major

Copyright:  unknown
Source:  McClatchy-Tribune Information Services
Wordcount:  947

Oct. 21--A computer flash drive containing the names, addresses, and personal health information of 280,000 people is missing -- one of the largest recent security breaches of personal health data in the nation.

"We deeply regret this unfortunate incident," said Jay Feldstein , the president of the two affiliated Philadelphia companies, Keystone Mercy Health Plan and AmeriHealth Mercy Health Plan.

The breach, which involves the records of Medicaid recipients, is the first such Medicaid data breach in Pennsylvania since at least 1997, according to the state's Department of Welfare, which has oversight.

"We take compliance [with federal privacy laws] very seriously," department spokeswoman Elisabeth Myers said Wednesday.

The security failure, one of the several largest in nearly two years, involves nearly two-thirds of the insurers' subscribers. It became known only after The Inquirer requested information Tuesday evening. The insurers said the drive was missing from the corporate offices on Stevens Drive in Southwest Philadelphia. It noted that the same flash drive was used at community health fairs.

"That seems grossly irresponsible," said Dr. Deborah Peel , a Texas psychiatrist who heads Patient Privacy Rights, an advocacy group.

"Why would you be hauling around private patient information to a health fair," she said. "I can't imagine what they were thinking, taking this data out of a locked room at company headquarters.

"What's tragic is that this is a particularly vulnerable group of people," Peel said. "They tend to be vulnerable to identity theft, vulnerable to discrimination." Medicaid recipients are low-income people.

The companies said that as of Tuesday, there had been no reports of anyone trying to use the information stored on the drive.

The news of the breach comes at a time when there is more emphasis -- and billions of dollars in federal funding -- to develop protocols for electronic medical records, with information being shared among providers, insurers, and consumers.

The idea is to eliminate duplicated record-keeping and improve patient health by allowing doctors, hospitals, and others to be quickly informed about medical conditions, prescriptions, allergies, and treatments.

"It's scary when you think about electronic patient records, which have many potential benefits, but there's also the concern about loss," said Susan Grant , director of consumer protection for the Consumer Federation of America, an association of nearly 300 consumer groups.

Paul Stephens , director of policy for the Privacy Rights Clearinghouse, said that data breaches in the finance and retail sectors tended to involve more people, but that health data are very sensitive and may also contain payment information.

The most infamous security breach occurred in 2006, when records of 2.65 million veterans were stolen from a Veterans Administration employee working from his home.

The Privacy Rights Clearinghouse in California maintains a database of reports on breaches culled from the media and websites. It listed 184 medical data incidents in 2009 and 2010 involving the records of 5.2 million people.

The Keystone and AmeriHealth case, if it had been listed, would have been among the top five by number of people involved.

In the Keystone and AmeriHealth case, the company said that of the 280,000 people affected only seven members' Social Security numbers were included on the flash drive, along with the last four Social Security numbers of an additional 801 clients.

The affiliated companies have been tight-lipped about the breach, which they said occurred Sept. 20.

Until The Inquirer asked for information, the company had not disclosed the data breach to affected members, most of whom live in Philadelphia and nearby counties.

Federal patient-privacy laws, which have been strengthened as the push toward electronic medical records advances, require that companies report major data breaches to the individuals, to the U.S. Secretary of Health and Human Resources, to the media, and to appropriate "business associates," in this case defined as the Pennsylvania Department of Public Welfare.

The federal website explaining the law says that breaches must be reported "without unreasonable delay and in no case later than 60 days."

Medicaid is funded jointly by federal and state governments. Pennsylvania's agreement appears to require a report within two days. Myers said it was unclear when the companies reported the incident. The federal government did not respond on time.

On Wednesday, the companies refused to offer any explanation of how the incident happened.

They would not say how they know the computer drive was lost, not stolen. They would not comment on the riskiness of taking the drive to health fairs, nor would they say whether the data on the drive was encrypted.

The companies refused to say whether they reported the incident to the federal government, as required.

At 4 p.m. Wednesday, after many requests for follow-up information, the companies issued this statement:

"At Keystone Mercy Health Plan and AmeriHealth Mercy Health Plan, our number one priority is our members. Since reporting this unfortunate incident to the Department of Public Welfare, we have actively and responsibly executed a multifaceted plan to inform those affected, while also evaluating and enhancing our security measures to ensure this does not happen again."

Keystone Mercy Health Plan provides insurance to 300,000 Medicaid members in Philadelphia, Bucks, Montgomery, Delaware, and Chester Counties. AmeriHealth serves 100,000 in a 15-county arc running from Harrisburg to northeastern Pennsylvania.

The two companies are jointly owned by Independence Blue Cross and the Mercy Health System.

Contact staff writer Jane M. Von Bergen at 215-854-2769 or [email protected].

To see more of The Philadelphia Inquirer, or to subscribe to the newspaper, go to http://www.philly.com/inquirer.

Copyright (c) 2010, The Philadelphia Inquirer

Distributed by McClatchy-Tribune Information Services.

For more information about the content services offered by McClatchy-Tribune Information Services (MCT), visit www.mctinfoservices.com, e-mail [email protected], or call 866-280-5210 (outside the United States, call +1 312-222-4544)

Older

Federal Agents Round Up Ring Of Mental Health Operators In Alleged $200 Million Fraud Case

Advisor News

  • Global economic growth will moderate as the labor force shrinks
  • Estate planning during the great wealth transfer
  • Main Street families need trusted financial guidance to navigate the new Trump Accounts
  • Are the holidays a good time to have a long-term care conversation?
  • Gen X unsure whether they can catch up with retirement saving
More Advisor News

Annuity News

  • Life insurance and annuities: Reassuring ‘tired’ clients in 2026
  • Insurance Compact warns NAIC some annuity designs ‘quite complicated’
  • MONTGOMERY COUNTY MAN SENTENCED TO FEDERAL PRISON FOR DEFRAUDING ELDERLY VICTIMS OF HUNDREDS OF THOUSANDS OF DOLLARS
  • New York Life continues to close in on Athene; annuity sales up 50%
  • Hildene Capital Management Announces Purchase Agreement to Acquire Annuity Provider SILAC
More Annuity News

Health/Employee Benefits News

  • New MERGE Research Finds Better Portal Design Is Key to Restoring Trust in Health Insurers
  • The Senate is set to vote on 2 rival health plans. Here's what's at stake for Americans
  • With Congress stalled on ACA subsidies, Nebraska Farm Bureau rolls out its own health plan
  • The ACA's enhanced subsidies seem likely to expire. Massachusetts is beginning to notice the effects
  • NEW JERSEY VOTERS UNDERSTAND HEALTH INSURANCE OPTIONS BUT WORRY ABOUT STATE GOVERNMENT'S INFLUENCE ON PLANS
Sponsor
More Health/Employee Benefits News

Life Insurance News

  • Life insurance and annuities: Reassuring ‘tired’ clients in 2026
  • Reliance Standard Life Insurance Company Trademark Application for “RELIANCEMATRIX” Filed: Reliance Standard Life Insurance Company
  • Jackson Awards $730,000 in Grants to Nonprofits Across Lansing, Nashville and Chicago
  • AM Best Affirms Credit Ratings of Lonpac Insurance Bhd
  • Reinsurance Group of America Names Ryan Krueger Senior Vice President, Investor Relations
More Life Insurance News

- Presented By -

Top Read Stories

More Top Read Stories >

NEWS INSIDE

  • Companies
  • Earnings
  • Economic News
  • INN Magazine
  • Insurtech News
  • Newswires Feed
  • Regulation News
  • Washington Wire
  • Videos

FEATURED OFFERS

Slow Me the Money
Slow down RMDs … and RMD taxes … with a QLAC. Click to learn how.

ICMG 2026: 3 Days to Transform Your Business
Speed Networking, deal-making, and insights that spark real growth — all in Miami.

Your trusted annuity partner.
Knighthead Life provides dependable annuities that help your clients retire with confidence.

Press Releases

  • SandStone Insurance Partners Welcomes Industry Veteran, Rhonda Waskie, as Senior Account Executive
  • Springline Advisory Announces Partnership With Software And Consulting Firm Actuarial Resources Corporation
  • Insuraviews Closes New Funding Round Led by Idea Fund to Scale Market Intelligence Platform
  • ePIC University: Empowering Advisors to Integrate Estate Planning Into Their Practice With Confidence
  • Altara Wealth Launches as $1B+ Independent Advisory Enterprise
More Press Releases > Add Your Press Release >

How to Write For InsuranceNewsNet

Find out how you can submit content for publishing on our website.
View Guidelines

Topics

  • Advisor News
  • Annuity Index
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • From the Field: Expert Insights
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Magazine
  • Insiders Only
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Washington Wire
  • Videos
  • ———
  • About
  • Advertise
  • Contact
  • Editorial Staff
  • Newsletters

Top Sections

  • AdvisorNews
  • Annuity News
  • Health/Employee Benefits News
  • InsuranceNewsNet Magazine
  • Life Insurance News
  • Property and Casualty News
  • Washington Wire

Our Company

  • About
  • Advertise
  • Contact
  • Meet our Editorial Staff
  • Magazine Subscription
  • Write for INN

Sign up for our FREE e-Newsletter!

Get breaking news, exclusive stories, and money- making insights straight into your inbox.

select Newsletter Options
Facebook Linkedin Twitter
© 2025 InsuranceNewsNet.com, Inc. All rights reserved.
  • Terms & Conditions
  • Privacy Policy
  • InsuranceNewsNet Magazine

Sign in with your Insider Pro Account

Not registered? Become an Insider Pro.
Insurance News | InsuranceNewsNet