Skip to content Skip to navigation

Major Data Breach at Premera Blue Cross Affects 11M Members

March 17, 2015
by Rajiv Leventhal
| Reprints

A massive data breach has hit the healthcare industry once again.

Premera Blue Cross, a Mountlake Terrace, Wash.-based health insurer, has acknowledged that it was victim of a cyber attack that could affect 11 million of its customers. On Jan. 29, Premera discovered that cyber attackers had executed a sophisticated attack to gain unauthorized access to its IT systems. The investigation further revealed that the initial attack occurred on May 5.

This incident affected Premera Blue Cross, Premera Blue Cross Blue Shield of Alaska, and its affiliate brands Vivacity and Connexion Insurance Solutions, Inc. Premera's investigation determined that the attackers may have gained unauthorized access to members' information, which could include members' name, date of birth, Social Security number, mailing address, email address, telephone number, member identification number, bank account information, and claims information, including clinical information. Individuals who do business with Premera and provided the company with their email address, personal bank account number, or Social Security number are also affected, the organization has said. As part of the investigation, Premera is working with the FBI as well as cybersecurity firm Mandiant to conduct a comprehensive investigation of the incident.

The investigation has not determined that any such data was removed from Premera's systems, and the organization also has no evidence to date that such data has been used inappropriately.  The payer is beginning to mail letters to approximately 11 million affected individuals on March 17, and is providing two years of free credit monitoring and identity theft protection services to those individuals. 

"The security of Premera's members' personal information remains a top priority. We at Premera take this issue seriously and sincerely regret the concern it may cause," Jeff Roe, CEO, Premera, said in a statement. "As much as possible, we want to make this event our burden, not that of the affected individuals, by making services available today to help protect people's information."

This attack comes only six weeks after the Indianapolis-based payer Anthem acknowledged that it suffered a massive hack of its IT systems that exposed the personal data of approximately 80 million customers.



EHNAC and HITRUST Combine HIPAA Security Criteria, CSF Framework

The Electronic Healthcare Network Accreditation Commission (EHNAC) and the Health Information Trust Alliance (HITRUST) announced plans to streamline their accreditation and certification programs.

Halamka on MACRA Final Rule: “CMS is Listening and I Thank Them”

Health IT notable expert John Halamka, M.D., CIO of Beth Israel Deaconess Medical Center in Boston, recently weighed in on the Medicare Access and CHIP Reauthorization Act (MACRA) final rule.

Texas Patient Care Clinic Hit with Ransomware Attack

Grand Prairie, Texas-based Rainbow Children's Clinic was the victim of a ransomware attack on its IT systems in August, affecting more than 33,000 patients, according to multiple news media reports this week.

Healthcare Organizations Again Go to Bat for AHRQ

Healthcare organizations are once again urging U.S. Senate and House leaders to protect the Department of Health and Human Services’ Agency for Healthcare Research and Quality (AHRQ) from more budget cuts for 2017.

ONC Pilot Projects Focus on Using, Sharing Patient-Generated Health Data

Accenture Federal Services (AFS) has announced two pilot demonstrations with the Office of the National Coordinator for Health Information Technology (ONC) to determine how patient-generated health data can be used by care teams and researchers.

Is it Unethical to Identify Patients as “Frequent Flyers” in Health IT Systems?

Several researchers from the University of Pennsylvania addressed the ethics of behavioral health IT as it relates to “frequent flyer” icons and the potential for implicit bias in an article published in JAMA.