Idaho A.G. Wasden Obtains Settlement From Health Insurer Premera Over Failure to Protect Sensitive Data From Hacker
"Despite repeated warnings about shortcomings in their systems, the company did not take the necessary steps to resolve those issues," Wasden said. "As a result, sensitive information was compromised. This settlement forces the company to take responsibility for sitting on its hands and ensures this won't be the case again."
An investigation revealed Premera's cybersecurity vulnerabilities gave a hacker unrestricted access to protected health information for almost a year. From
The hacker took advantage of multiple known weaknesses in Premera's data security. For years prior to the breach, cybersecurity experts and the company's own auditors repeatedly warned Premera of its inadequate security program, yet the company accepted many of the risks without fixing its practices.
The complaint asserts that Premera misled consumers about its privacy practices in the aftermath of the data breach. After the breach became public, Premera's call center agents told consumers there was "no reason to believe that any of your information was accessed or misused." They also told consumers that "there were already significant security measures in place to protect your information," despite the previous warnings over the company's vulnerabilities.
Today's settlement also requires Premera to:
* Ensure its data security program protects personal health information as required by law.
* Regularly assess and update its security measures.
* Provide the states with data security reports, completed by a third-party security expert.
* Hire a chief information security officer experienced in data security and HIPAA compliance.
Hold regular meetings between the chief information security officer and Premera's executive management. The information security officer must inform the CEO of any unauthorized intrusion into the Premera network within 48 hours of discovery.
‘It’s powerful’: Tropical storm starts lashing Louisiana
Montana A.G. Fox: Attorney General Fox Obtains Data Breach Settlement From Premera Blue Cross
Advisor News
Annuity News
Health/Employee Benefits News
Life Insurance News