Montana A.G. Fox: Attorney General Fox Obtains Data Breach Settlement From Premera Blue Cross
Attorney General
In today's complaint, filed simultaneously with the terms of the negotiated settlement, Attorney General Fox asserts the company failed to meet its obligations under the federal Health Insurance Portability and Accountability Act (HIPAA) and violated the state Consumer Protection Act by not addressing known cybersecurity vulnerabilities that gave a hacker unrestricted access to protected health information for almost one year. "This litigation marks the first time
From
Under the settlement, Premera will pay a combined total of
The complaint asserts that Premera misled consumers nationwide about its privacy practices in the aftermath of the data breach. After the breach became public, Premera's call center agents told consumers there was "no reason to believe that any of your information was accessed or misused." They also told consumers that "there were already significant security measures in place to protect your information," even though multiple security experts and auditors warned the company of its security vulnerabilities prior to the breach.
Under HIPAA, Premera is required to implement administrative, physical and technical safeguards that reasonably and appropriately protect sensitive consumer information. Premera repeatedly failed to meet these standards, leaving millions of consumer's sensitive data vulnerable to hackers.
Today's settlement also requires Premera to:
* Ensure its data security program protects personal health information as required by law;
* Regularly assess and update its security measures;
* Provide data security reports, completed by a third-party security expert approved by the multistate coalition, to the
* Hire a chief information security officer, a separate position from the chief information officer. The information security officer must be experienced in data security and HIPAA compliance and will be responsible for implementing, maintaining and monitoring the company's security program;
* Hold regular meetings between the chief information security officer and Premera's executive management. The information security officer must meet with Premera's CEO every two months and inform the CEO of any unauthorized intrusion into the Premera network within 48 hours of discovery.
In addition to
If any Montanans believe they have been the victim of identity theft resulting from this breach or any other, they can contact



Barry’s outer bands begin hitting southeastern Louisiana
Nevada A.G. Ford Joins Multistate Settlement Against Premera for Failure to Protect Sensitive Data of Millions Nationwide
Advisor News
- CFP Board appoints K. Dane Snowden as CEO
- TIAA unveils ‘policy roadmap’ to boost retirement readiness
- 2026 may bring higher volatility, slower GDP growth, experts say
- Why affluent clients underuse advisor services and how to close the gap
- America’s ‘confidence recession’ in retirement
More Advisor NewsAnnuity News
- Insurer Offers First Fixed Indexed Annuity with Bitcoin
- Assured Guaranty Enters Annuity Reinsurance Market
- Ameritas: FINRA settlement precludes new lawsuit over annuity sales
- Guaranty Income Life Marks 100th Anniversary
- Delaware Life Insurance Company Launches Industry’s First Fixed Indexed Annuity with Bitcoin Exposure
More Annuity NewsHealth/Employee Benefits News
- Illinois Medicaid program faces looming funding crisis due to federal changes
- Recent Research from Medical College of Wisconsin Highlight Findings in Managed Care and Specialty Pharmacy (Differences In Glp-1 Ra Medication Adherence Across Place-based Variables In Patients With Diabetes Living In Wisconsin): Drugs and Therapies – Managed Care and Specialty Pharmacy
- Trademark Application for “NAYYA” Filed by Nayya Health, Inc.: Nayya Health Inc.
- Researchers at Augusta University Target Managed Care (The importance and challenge of comparing stroke care, utilization and outcomes in Medicare Advantage and Fee-for-Service Medicare: a narrative review and vision for the future): Managed Care
- Researchers’ Work from Oregon Health & Science University (OHSU) Focuses on Managed Care (Evaluating variation between states in algorithms used for identifying abortions in Medicaid claims data): Managed Care
More Health/Employee Benefits NewsLife Insurance News