Data Breach at BlueCross BlueShield Business Associate Potentially Exposes 3.3 Million Members’ Data | Healthcare Informatics Magazine | Health IT | Information Technology Skip to content Skip to navigation

Data Breach at BlueCross BlueShield Business Associate Potentially Exposes 3.3 Million Members’ Data

August 8, 2016
by Heather Landi
| Reprints
Click To View Gallery

Albany, New York-based Newkirk Products, a company that issues healthcare ID cards for health insurance plans, reported a cyber security incident involving unauthorized access to a server containing approximately 3.3 million plan members’ personal information.

The company provides insurance cards to Blue Cross and Blue Shield of Kansas City, Blue Cross Blue Shield of North Carolina, HealthNow New York Inc., BlueCross BlueShield of Western New York, BlueShield of Northeastern New York, and Capital District Physicians' Health Plan, Inc. (CDPHP), and, through Newkirk’s relationship as a service provider to DST Health Solutions, Inc., Gateway Health Plan, Highmark Health Options, West Virginia Family Health, Johns Hopkins Employer Health Programs, Inc., Priority Partners Managed Care Organization and Uniformed Services Family Health Plan.

The company posted a notice of data breach on a dedicated website page last Friday and stated that no health plans’ systems were accessed or affected.

According to the company’s statement, the data potentially subject to unauthorized access varies by plan but includes some combination of the member’s names, mailing address, type of plan, member and group ID number, names of dependents enrolled in the plan, primary care provider, and in some cases, date of birth, premium invoice information and Medicaid ID number.

“The server did not contain Social Security numbers, banking or credit card information, medical information or any insurance claims information,” the company stated.

On a frequency asked questions page, the company reported that approximately 3.3 million members of the identified plans were affected by the security incident. And, the company stated that although the information contained on the server may have been accessed, the company has no evidence to date that such data has been used inappropriately.

Newkirk was acquired by Broadridge Financial Solutions from DST Systems, Inc. on July 1. According to the company’s statement about the breach, five days after the sale closed, on July 6, Newkirk discovered that a server containing member information was accessed without authorization. Newkirk shut down the server, started an investigation into the incident and hired a third party forensic investigator to determine the extent of the unauthorized access and whether the personal information of its clients’ members may have been accessed. Newkirk also notified federal law enforcement. According to the ongoing forensic investigation, it appears that the unauthorized access first occurred on May 21, 2016.

Newkirk also stated that the network of its parent company, Broadridge, was not compromised, as the Newkirk network has not been integrated into Broadridge.

The company has mailed out letters to those impacted, including an explanation of the incident, an offer of two years of free identity protection and information about additional ways impacted individuals can protect themselves.

Get the latest information on Health IT and attend other valuable sessions at this two-day Summit providing healthcare leaders with educational content, insightful debate and dialogue on the future of healthcare and technology.

Learn More



Survey: Infrastructure, Interoperability Key Barriers to Global HIT Development

A new survey report from Black Book Research on global healthcare IT adoption and records systems connectivity finds nations in various phases of regional electronic health record (EHR) adoption. The survey results also reveal rapidly advancing opportunities for U.S.-based and local technology vendors.

Penn Medicine Opens Up Telehealth Hub

Philadelphia-based Penn Medicine has opened its Center for Connected Care to centralize the health system’s telemedicine activities.

Roche to Pay $1.9B for Flatiron Health

Switzerland-based pharmaceutical company Roche has agreed to pay $1.9 billion to buy New York-based Flatiron Health Inc., which has both an oncology EHR and data analytics platform.

Financial Exec Survey: Interoperability Key Obstacle to Value-Based Payment Models

Momentum continues to grow for value-based care as nearly three-quarters of healthcare executives report their organizations have achieved positive financial results from value-based payment programs, to date, according to a new study from the Healthcare Financial Management Association (HFMA).

Cerner, Children's National to Help UAE Pediatric Center with Health IT

Al Jalila Children's Specialty Hospital, the only pediatric hospital in the United Arab Emirates, has entered into an agreement with Washington, D.C.-based Children's National Health System to form a health IT strategic partnership.

Telemedicine Association Names New CEO

The American Telemedicine Association (ATA) has named Ann Mond Johnson its new CEO, replacing Jon Linkous who stepped down suddenly last August after 24 years as the organization’s CEO.