Desk live·
ForensicPost
Insurance/Health/File 09-1002

BCBS of Tennessee Lost 57 Hard Drives Holding 1 Million Members’ Call Recordings

The drives were taken from a network closet in a leased former call centre in Chattanooga. They held recorded customer-service calls with Social Security numbers and diagnoses spoken aloud. The $1.5 million federal settlement was the first under the breach-notification law.

Constructed geometry · not a chart of case data
JurisdictionUSAChattanoogathe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetBlueCross BlueShield of Tennessee
ActorUnattributed
D. Kennedy9 min readConfidence: high3 sources reviewed

On or about Oct. 2, 2009, 57 hard drives were stolen from a network data closet at a leased facility in Chattanooga, Tennessee, that BlueCross BlueShield of Tennessee had used as a call centre. The drives held about 1 million audio recordings and 300,000 screen recordings of customer-service calls made between Jan. 1, 2007, and the day of the theft. Callers had given their names, Social Security numbers, birth dates, plan identification numbers and diagnosis codes on those calls.

The recordings were encoded but not encrypted. The insurer first notified about 220,000 people, expanded that to 520,000 by February 2010 and eventually reported more than 1 million affected to the Department of Health and Human Services.

The First Enforcement Of The Notification Law

On March 13, 2012, HHS announced a $1.5 million settlement with the insurer and a corrective action plan. The agency said it was the first enforcement action to arise from a breach reported under the HITECH Act’s notification requirement, which had taken effect in September 2009, a matter of days before the theft. Investigators found the company had not performed a security evaluation after moving out of the facility and had not maintained adequate physical access controls.

The company put its own response cost at more than $7 million by February 2010 and about $17 million in total, according to contemporaneous reporting. The penalty was less than a tenth of what the breach had already cost.

A Recording Is A Record

The file is here because of what the data was. A call recording is the member’s own voice stating the fields an identity thief needs, with the diagnosis attached. It cannot be redacted after the fact and was never designed to be searched, which is why nobody had thought to encrypt it. The sector spent the following decade learning that the copy of the data nobody thinks of as a database is the copy that leaves.

How we reported this

Compiled from the HHS announcement and resolution agreement and from contemporaneous trade reporting, listed below. The count rose over time and is given at each stage with its source. No attribution exists; the theft was never solved in the material reviewed. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. HHS settles HIPAA case with BCBST for $1.5 millionU.S. Department of Health and Human Services
  2. BCBS Notifying 520,000 About BreachHealthcareInfoSecurity
  3. Tennessee insurer to pay $1.5 million for breach-related violationsComputerworld
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary