Server breach impacts major California insurer, 4.5M patient records at risk

A file transfer platform used by a major insurer in California may have a vulnerability that caused a massive data breach, potentially exposing millions of patient records to cybercriminals. 

Blue Shield of California notified the public about the breach in November, saying personal information including names, birth dates, Social Security numbers and patient ID numbers, as well as personal data on the diagnoses and care patients received, may have been accessed by hackers.

The insurer has 4.5 million members, but the notice does not specify how many individuals are impacted. According to coverage from the East Bay Times, despite the notice from Blue Shield being dated Nov. 10, members only received word last week. 

According to the statement, a service called MOVEit, which Blue Shield uses to transfer and store sensitive patient information, was the victim of the breach. The insurer was notified on Sept. 1 of the attack, which an investigation concluded took place between May 28 and 31.

Only the MOVEit server was compromised, with Blue Shield saying their internal emails and systems were not accessed.

MOVEit is a contractor for other insurers, academic institutions and technology companies, and this latest announcement is only one of many involving the same server breach. In July, the Centers for Medicare and Medicaid services announced 612,000 patients were affected when their personal health information was impacted. 

In its notice, Blue Shield said it is providing “members impacted by the MOVEit file transfer tool security breach” with “no-cost credit monitoring and identity restoration services.” 

 

Chad Van Alstin Health Imaging Health Exec

Chad is an award-winning writer and editor with over 15 years of experience working in media. He has a decade-long professional background in healthcare, working as a writer and in public relations.

Around the web

The tirzepatide shortage that first began in 2022 has been resolved. Drug companies distributing compounded versions of the popular drug now have two to three more months to distribute their remaining supply.

The 24 members of the House Task Force on AI—12 reps from each party—have posted a 253-page report detailing their bipartisan vision for encouraging innovation while minimizing risks. 

Merck sent Hansoh Pharma, a Chinese biopharmaceutical company, an upfront payment of $112 million to license a new investigational GLP-1 receptor agonist. There could be many more payments to come if certain milestones are met.