Skip to content Skip to navigation

Data Breach at BlueCross BlueShield Business Associate Potentially Exposes 3.3 Million Members’ Data

August 8, 2016
by Heather Landi
| Reprints
Click To View Gallery

Albany, New York-based Newkirk Products, a company that issues healthcare ID cards for health insurance plans, reported a cyber security incident involving unauthorized access to a server containing approximately 3.3 million plan members’ personal information.

The company provides insurance cards to Blue Cross and Blue Shield of Kansas City, Blue Cross Blue Shield of North Carolina, HealthNow New York Inc., BlueCross BlueShield of Western New York, BlueShield of Northeastern New York, and Capital District Physicians' Health Plan, Inc. (CDPHP), and, through Newkirk’s relationship as a service provider to DST Health Solutions, Inc., Gateway Health Plan, Highmark Health Options, West Virginia Family Health, Johns Hopkins Employer Health Programs, Inc., Priority Partners Managed Care Organization and Uniformed Services Family Health Plan.

The company posted a notice of data breach on a dedicated website page last Friday and stated that no health plans’ systems were accessed or affected.

According to the company’s statement, the data potentially subject to unauthorized access varies by plan but includes some combination of the member’s names, mailing address, type of plan, member and group ID number, names of dependents enrolled in the plan, primary care provider, and in some cases, date of birth, premium invoice information and Medicaid ID number.

“The server did not contain Social Security numbers, banking or credit card information, medical information or any insurance claims information,” the company stated.

On a frequency asked questions page, the company reported that approximately 3.3 million members of the identified plans were affected by the security incident. And, the company stated that although the information contained on the server may have been accessed, the company has no evidence to date that such data has been used inappropriately.

Newkirk was acquired by Broadridge Financial Solutions from DST Systems, Inc. on July 1. According to the company’s statement about the breach, five days after the sale closed, on July 6, Newkirk discovered that a server containing member information was accessed without authorization. Newkirk shut down the server, started an investigation into the incident and hired a third party forensic investigator to determine the extent of the unauthorized access and whether the personal information of its clients’ members may have been accessed. Newkirk also notified federal law enforcement. According to the ongoing forensic investigation, it appears that the unauthorized access first occurred on May 21, 2016.

Newkirk also stated that the network of its parent company, Broadridge, was not compromised, as the Newkirk network has not been integrated into Broadridge.

The company has mailed out letters to those impacted, including an explanation of the incident, an offer of two years of free identity protection and information about additional ways impacted individuals can protect themselves.



EHNAC and HITRUST Combine HIPAA Security Criteria, CSF Framework

The Electronic Healthcare Network Accreditation Commission (EHNAC) and the Health Information Trust Alliance (HITRUST) announced plans to streamline their accreditation and certification programs.

Halamka on MACRA Final Rule: “CMS is Listening and I Thank Them”

Health IT notable expert John Halamka, M.D., CIO of Beth Israel Deaconess Medical Center in Boston, recently weighed in on the Medicare Access and CHIP Reauthorization Act (MACRA) final rule.

Texas Patient Care Clinic Hit with Ransomware Attack

Grand Prairie, Texas-based Rainbow Children's Clinic was the victim of a ransomware attack on its IT systems in August, affecting more than 33,000 patients, according to multiple news media reports this week.

Healthcare Organizations Again Go to Bat for AHRQ

Healthcare organizations are once again urging U.S. Senate and House leaders to protect the Department of Health and Human Services’ Agency for Healthcare Research and Quality (AHRQ) from more budget cuts for 2017.

ONC Pilot Projects Focus on Using, Sharing Patient-Generated Health Data

Accenture Federal Services (AFS) has announced two pilot demonstrations with the Office of the National Coordinator for Health Information Technology (ONC) to determine how patient-generated health data can be used by care teams and researchers.

Is it Unethical to Identify Patients as “Frequent Flyers” in Health IT Systems?

Several researchers from the University of Pennsylvania addressed the ethics of behavioral health IT as it relates to “frequent flyer” icons and the potential for implicit bias in an article published in JAMA.