State senator DiPalma wants answers on how RIPTA breach happened — so there isn't a repeat [The Providence Journal] - Insurance News | InsuranceNewsNet

InsuranceNewsNet — Your Industry. One Source.™

Sign in
  • Subscribe
  • About
  • Advertise
  • Contact
Home Now reading Newswires
Topics
    • Advisor News
    • Annuity Index
    • Annuity News
    • Companies
    • Earnings
    • Fiduciary
    • From the Field: Expert Insights
    • Health/Employee Benefits
    • Insurance & Financial Fraud
    • INN Magazine
    • Insiders Only
    • Life Insurance News
    • Newswires
    • Property and Casualty
    • Regulation News
    • Sponsored Articles
    • Washington Wire
    • Videos
    • ———
    • About
    • Meet our Editorial Staff
    • Advertise
    • Contact
    • Newsletters
  • Exclusives
  • NewsWires
  • Magazine
  • Newsletters
Sign in or register to be an INNsider.
  • AdvisorNews
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Exclusives
  • INN Magazine
  • Insurtech
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Video
  • Washington Wire
  • Life Insurance
  • Annuities
  • Advisor
  • Health/Benefits
  • Property & Casualty
  • Insurtech
  • About
  • Advertise
  • Contact
  • Editorial Staff

Get Social

  • Facebook
  • X
  • LinkedIn
Newswires
Newswires RSS Get our newsletter
Order Prints
January 6, 2022 Newswires
Share
Share
Post
Email

State senator DiPalma wants answers on how RIPTA breach happened — so there isn't a repeat [The Providence Journal]

Providence Journal (RI)

The Rhode Island Public Transit Authority data breach that compromised thousands of state workers' personal information raises numerous questions about the state's protocols for dealing with sensitive data, according Sen. Louis P. DiPalma, D-Middletown.

Among them: Who within RIPTA received files containing personal information about state workers with no connection to the agency? Why was that data not deleted?

And do we know where else similar data might be stored on state servers?

"We're talking about 17,000 individuals that are impacted, and could be impacted for life," DiPalma said. "How do we ensure this doesn't happen again?"

RIPTA revealed in late December that hackers had obtained files that contained information including Social Security numbers, birthdates, addresses and the dates and dollar amounts of health claims. The breach took place in early August, and involved data belonging to both past and present employees who were on the state's health plan, as well as their beneficiaries.

'Reviewing this incident': Attorney general will probe whether RIPTA's handling of data breach complied with the law

That data was "incorrectly shared" with RIPTA by the state's previous health insurance provider, according to a lengthy FAQ document that was sent to state employees by the Department of Administration on Wednesday morning.

The state's current health insurer is Blue Cross/Blue Shield of Rhode Island.

A spokesman for UnitedHealthcare provided the following statement on Thursday: "We were privileged to administer the health benefits plan for the State of Rhode Island employees and their families from May 2005 through December 2019. Protecting sensitive member information is a key priority for us. Although this data breach did not affect any UnitedHealthcare system, we share public officials' interest in understanding the facts and are available to cooperate with authorities on their investigation."

Meanwhile, the office of Health Insurance Commissioner Patrick Tigue is "conducting a due-diligence review to understand the role that the state's former third party administrator for state employee health benefits is alleged to have played in producing the data that was provided to RIPTA and later stolen," Tigue's chief of staff, Cory King, wrote in an email.

DiPalma said it will be important to know exactly how the data was shared with RIPTA: Was it in an email to the transit agency, or did someone at RIPTA have to click a link to gain access?

"Neither one is good," he said — but it's context that's necessary because avoiding a repeat requires knowing more about how RIPTA acquired the data in the first place. Similarly, it's important to know how long the data was sitting on RIPTA's servers, and if it was all shared with RIPTA on one occasion or in separate incidents that span multiple years.

Hacker hit RIPTA: Here's why over 17,000 state employees discovered their data was stolen

Initially, the DOA told state workers that the compromised files appeared to contain information from 2013 to 2015. The agency has since corrected that statement, saying "the subject period of the data files extends to a currently undetermined point in early 2020."

IT officials should do a "sweep" to find out where else information like Social Security numbers is being stored, who has access to it and why it's there, DiPalma previously told The Journal.

The state's Department of Information Technology did not respond to an inquiry on Tuesday. The DOA's FAQ says that RIPTA is now "taking all necessary steps to remove all files containing state employee information," and that the state is "working closely with all parties involved" to prevent a repeat.

"Someone at some point should have raised their hands and said, 'Should I have this?'" DiPalma said. He's seeking clarity on whether there was a protocol in place that should have been followed — which might indicate that there needs to be more training so that state employees are aware of what to do if they inadvertently end up possessing sensitive data in the future.

"There's still many more questions to be answered for us to have a complete understanding of the situation, and I'll be looking to get those answers," DiPalma said.

In Providence:: Elorza proposes millions for housing, reparations in new COVID-relief fund spending plan

RIPTA has not answered questions about who received the data that was improperly shared with the agency, and why it wasn't deleted.

"As the situation continues to be examined, it is important to note that RIPTA has complied with and fulfilled all of its legal obligations and continues to cooperate fully with the attorney general's investigation," senior executive officer Courtney Marciano said in an email. "Though the event is certainly unfortunate, we are handling the situation with the extreme seriousness it requires, while taking a hard look at the security measures in place and finding any and all ways to improve them going forward."

The exact number of people whose data was stolen in the RIPTA breach has been an ongoing source of confusion.

Letters mailed out to victims state that the incident "involves 17,378 people in Rhode Island." But the Rhode Island attorney general's office was told that the files contained personal information from "over 12,700 Rhode Island residents," spokeswoman Kristy dosReis said last week.

Winter storm watch: 4 to 6 inches of snow likely Friday, heavy during morning commute

A third number can be found on the U.S. Department of Health and Human Services' online data portal, which indicates that only 5,015 people were affected by the breach.

Marciano said on Wednesday that the discrepancy reflects that "the total number of individuals whose personal health information was affected by the incident pursuant to HIPAA" was 5,015.

Rhode Island law requires people to be notified about any breach that "poses a significant risk of identity theft," so it's not limited to instances where health data was compromised and HIPAA guidelines would apply. RIPTA sent out notifications to a total of 17,378 people in accordance with that law, Marciano said.

According to the DOA, employees who received a letter saying that their personal data had been compromised are "encouraged to actively monitor for the possibility of fraud and identity theft by reviewing your credit reports and account statements for any unauthorized activity regularly," and sign up for the free credit monitoring provided by RIPTA.

Receiving a letter doesn't necessarily mean that you have been a victim of identity fraud, the guidance notes.

RIPTA did not say who would be footing the bill for the full year of Equifax credit monitoring that is being offered to people whose information was compromised.

This story has been updated to include comments from UnitedHealthcare.

©2022 www.providencejournal.com. Visit providencejournal.com. Distributed by Tribune Content Agency, LLC.

Older

State senator DiPalma wants answers on how RIPTA breach happened — so there isn't a repeat [The Providence Journal]

Newer

Insurance protection for emergency situations

Advisor News

  • Addressing the ‘menopause tax:’ A guide for advisors with female clients
  • Alternative investments in 401(k)s: What advisors must know
  • The modern advisor: Merging income, insurance, and investments
  • Financial shocks, caregiving gaps and inflation pressures persist
  • Americans unprepared for increased longevity
More Advisor News

Annuity News

  • Globe Life Inc. (NYSE: GL) Making Surprising Moves in Monday Session
  • Aspida Life and WealthVest Offer a Powerful New Guaranteed Income Product with the WealthLock® Income Builder
  • Lack of digital tools drives wedge between insurers, advisors
  • LIMRA: Annuity sales notch 10th consecutive $100B+ quarter
  • AIG to sell remaining shares in Corebridge Financial
More Annuity News

Health/Employee Benefits News

  • Studies from Denise Wolff et al Have Provided New Data on Atopic Dermatitis (AMCP Market Insights: Beyond skin deep on the role of managed care in moderate to severe atopic dermatitis): Skin Diseases and Conditions – Atopic Dermatitis
  • New Clinical Trials and Studies Findings from RAND Corporation Described (Benefit design and consumer information: results from a randomized trial): Clinical Research – Clinical Trials and Studies
  • School, BOCES healthcare costs up 22%, here’s why
  • Healthcare cuts threaten Sullivan's reelection chances in Alaska
  • Health insurance marketplace feels growing tremors from GOP cuts
More Health/Employee Benefits News

Life Insurance News

  • Globe Life Inc. (NYSE: GL) Making Surprising Moves in Monday Session
  • Dan Scholz to receive NAIFA’s Terry Headley Lifetime Defender Award
  • Best’s Special Report: US Property/Casualty and Health Insurers Exceed Cost of Capital; Life Insurers Narrowly Miss
  • Aspida Life and WealthVest Offer a Powerful New Guaranteed Income Product with the WealthLock® Income Builder
  • Lack of digital tools drives wedge between insurers, advisors
More Life Insurance News

- Presented By -

NEWS INSIDE

  • Companies
  • Earnings
  • Economic News
  • INN Magazine
  • Insurtech News
  • Newswires Feed
  • Regulation News
  • Washington Wire
  • Videos

FEATURED OFFERS

Why Blend in When You Can Make a Splash?
Pacific Life’s registered index-linked annuity offers what many love about RILAs—plus more!

Life moves fast. Your BGA should, too.
Stay ahead with Modern Life's AI-powered tech and expert support.

Bring a Real FIA Case. Leave Ready to Close.
A practical working session for agents who want a clearer, repeatable sales process.

Discipline Over Headline Rates
Discover a disciplined strategy built for consistency, transparency, and long-term value.

Inside the Evolution of Index-Linked Investing
Hear from top issuers and allocators driving growth in index-linked solutions.

Press Releases

  • Sequent Planning Recognized on USA TODAY’s Best Financial Advisory Firms 2026 List
  • Highland Capital Brokerage Acquires Premier Financial, Inc.
  • ePIC Services Company Joins wealth.com on Featured Panel at PEAK Brokerage Services’ SPARK! Event, Signaling a Shift in How Advisors Deliver Estate and Legacy Planning
  • Hexure Offers Real-Time Case Status Visibility and Enhanced Post-Issue Servicing in FireLight Through Expanded DTCC Partnership
  • RFP #T01325
More Press Releases > Add Your Press Release >

How to Write For InsuranceNewsNet

Find out how you can submit content for publishing on our website.
View Guidelines

Topics

  • Advisor News
  • Annuity Index
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • From the Field: Expert Insights
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Magazine
  • Insiders Only
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Washington Wire
  • Videos
  • ———
  • About
  • Meet our Editorial Staff
  • Advertise
  • Contact
  • Newsletters

Top Sections

  • AdvisorNews
  • Annuity News
  • Health/Employee Benefits News
  • InsuranceNewsNet Magazine
  • Life Insurance News
  • Property and Casualty News
  • Washington Wire

Our Company

  • About
  • Advertise
  • Contact
  • Meet our Editorial Staff
  • Magazine Subscription
  • Write for INN

Sign up for our FREE e-Newsletter!

Get breaking news, exclusive stories, and money- making insights straight into your inbox.

select Newsletter Options
Facebook Linkedin Twitter
© 2026 InsuranceNewsNet.com, Inc. All rights reserved.
  • Terms & Conditions
  • Privacy Policy
  • InsuranceNewsNet Magazine

Sign in with your Insider Pro Account

Not registered? Become an Insider Pro.
Insurance News | InsuranceNewsNet