Report Indicates Premera Knew of Vulnerabilities Before Breach | Healthcare Informatics Magazine | Health IT | Information Technology Skip to content Skip to navigation

Report Indicates Premera Knew of Vulnerabilities Before Breach

March 19, 2015
by Gabriel Perna
| Reprints

A government agency warned health insurer Premera that its data protection practices were not up to industry standards right before it was victimized by a major cyber attack.

The report, from the U.S. Office of Personnel Management's Office of the Inspector General, was released on Apr. 17, 2014. One month later, Premera was a victim of a cyber attack that affected up to 11 million of its customers, the Mountlake Terrace, Wash.-based company revealed this week. The company had discovered the breach in late January.

The report details Premera’s lack of thorough network security controls, saying the company’s patches were not being implemented in a timely manner and there had been no methodology to ensure unsupported out-of-date software is not utilized; and it had an insecure server configuration. Importantly, the authors said that its vulnerability scan revealed that several servers contained insecure configurations that could allow hackers access to sensitive information. Premera promised to “remediate” that last one by the end of 2014.

Furthermore, the authors of the report noted the physical access controls to the Premera’s data center could have been improved and lack of compliance with its password policy. It also said that Premera’s disaster recovery testing planning methods could be improved, which the insurer disagreed with in its response.

In an interview with The Seattle Times, a spokesperson for the company said the concerns outlined in the audit and the hack were separate issues.

Premera is the second major payer to be the victim of a cyber attack. Anthem, a large Indianapolis-based payer, suffered a massive hack of its IT systems in February that exposed the personal data of approximately 80 million customers.

Topics

News

Appalachia Project to Study Relationship Between Increased Broadband Access, Improved Cancer Care

The Federal Communications Commission and the National Cancer Institute have joined forces to focus on how increasing broadband access and adoption in rural areas can improve the lives of rural cancer patients.

Survey: By 2019, 60% of Medicare Revenues will be Tied to Risk

Medical groups and health systems that are members of AMGA (the American Medical Group Association) expect that nearly 60 percent of their revenues from Medicare will be from risk-based products by 2019, according to the results from a recent survey.

83% of Physicians Have Experienced a Cyber Attack, Survey Finds

Eighty-three percent of physicians in a recent survey said that they have experienced some sort of cyber attack, such as phishing and viruses.

Community Data Sharing: Eight Recommendations From San Diego

A learning guide focuses on San Diego’s experience in building a community health information exchange and the realities of embarking on a broad community collaboration to achieve better data sharing.

HealthlinkNY’s Galanis to Step Down as CEO

Christina Galanis, who has served as president and CEO of HealthlinkNY for the past 13 years, will leave her position at the end of the year.

Email-Related Cyber Attacks a Top Concern for Providers

U.S. healthcare providers overwhelmingly rank email as the top source of a potential data breach, according to new research from email and data security company Mimecast and conducted by HIMSS Analytics.