Excellus BlueCross BlueShield Hacked; More Than 10M Affected | Healthcare Informatics Magazine | Health IT | Information Technology Skip to content Skip to navigation

Excellus BlueCross BlueShield Hacked; More Than 10M Affected

September 10, 2015
by Heather Landi
| Reprints

Excellus BlueCross BlueShield, a Rochester, N.Y.-based insurer, was the target of a sophisticated cyber attack of its IT systems that exposed the personal data of more than 10 million people.

The payer and its affiliates disclosed late in the day on Sept. 9 that Excellus discovered the unauthorized access into their computer systems on Aug. 5 and upon further investigation working with cyber security firm Mandiant it was determined that the initial security breach occurred 20 months prior, on December 23, 2013.

This hacking incident marks the latest in a number of high profile cyber attacks on healthcare organizations, including the massive hack on Anthem in February, which exposed approximately 80 million records, as well as a large data breach at UCLA Health Systems in July which potentially affected 4.5 million people.

Excellus president and CEO Christopher Booth said in a message to customers posted on the organization’s website that an investigation determined hackers may have gained unauthorized access to individuals’ information, which could include name, date of birth, Social Security number, mailing address, telephone number, member identification number, financial account information and claims information.

The organization said that its internal investigation has not determine that any such data was removed from its systems and there is no evidence to date that such data has been used inappropriately. The company notified the Federal Bureau of Investigation (FBI) and is coordinating with the bureau’s investigation.

In a recent interview with Healthcare Informatics, Ron Mehring, the senior director, chief information security officer at Dallas-based Texas Health Resources, addressed the information security risks facing healthcare organizations and spoke specifically to the lessons learned from the data breaches at Anthem and UCLA Health.

“Be prepared and have a plan,” Mehring told HCI. “From what I have learned, and Anthem especially has been very transparent on the way they handled those breaches, you need to make sure you have a great response plan and be prepared for that inevitable breach at the tactical and technical level, but also at your executive level. You need to make sure that everyone understands that it could happen and have a plan.”

This latest attack affected about 7 million Excellus members and 3.5 million members of its non-BlueCross BlueShield subsidiary, Lifetime Healthcare Companies. Other affiliates are Lifetime Benefit Solutions, Lifetime Care, Lifetime Health Medical Group, The Med America Companies and Universa Healthcare. In the statement on the company website, Booth said the incident also affected members of other BlueCross BlueShield plans who sought treatment in the 31 county upstate New York service area of Excellus BSBS as well as individuals who do business with the payer and provided their financial information or Social Security number.

Excellus is notifying affected customers and offering identity theft protection services through Kroll, a risk mitigation and response solution company, including credit monitoring through TransUnion as a precaution against reuse of stolen personal data.

As has been previously reported in Healthcare Informatics, it can be very costly for healthcare organizations to recover from a data breach. A survey from Ponemon Institute found that healthcare organizations spent an average of more than $2 million to resolve the consequences of a data breach involving an average of almost more than 2,700 lost or stolen records. Another study from Ponemon and IBM revealed that healthcare emerged as the industry with the highest cost per stolen record with the average cost for organizations reaching as high as $363.

Get the latest information on Health IT and attend other valuable sessions at this two-day Summit providing healthcare leaders with educational content, insightful debate and dialogue on the future of healthcare and technology.

Learn More



NIH Releases First Dataset from Adolescent Brain Development Study

The National Institutes of Health (NIH) announced the release of the first dataset from the Adolescent Brain Cognitive Development (ABCD) study, which will enable scientists to conduct research on the many factors that influence brain, cognitive, social, and emotional development.

Boston Children's Accelerates Data-Driven Approach to Clinical Research

In an effort to bring a more data-driven approach to clinical research, Boston Children’s Hospital has joined the TriNetX global health research network.

Paper Records, Films Most Common Type of Healthcare Data Breach, Study Finds

Despite the high level of hospital adoption of electronic health records and federal incentives to do so, paper and films were the most frequent location of breached data in hospitals, according to a recent study.

AHA Appoints Senior Advisor for Cybersecurity and Risk

The American Hospital Association (AHA) has announced that John Riggi has joined the association as senior advisor for cybersecurity and risk.

Report: Healthcare Accounted for 45% of All Ransomware Attacks in 2017

Healthcare fell victim to more ransomware attacks than any other industry in 2017, according to a new report from global cybersecurity insurance company Beazley.

Study: Use of EHRs Does Not Reduce Administrative Costs

A recent study by Duke University and Harvard Business School researchers found that costs for processing a single bill ranged from $20 for a primary care visit to $215 for an inpatient surgical procedure, or up to 25 percent of revenue.