On or about Oct. 2, 2009, 57 hard drives were stolen from a network data closet at a leased facility in Chattanooga, Tennessee, that BlueCross BlueShield of Tennessee had used as a call centre. The drives held about 1 million audio recordings and 300,000 screen recordings of customer-service calls made between Jan. 1, 2007, and the day of the theft. Callers had given their names, Social Security numbers, birth dates, plan identification numbers and diagnosis codes on those calls.
The recordings were encoded but not encrypted. The insurer first notified about 220,000 people, expanded that to 520,000 by February 2010 and eventually reported more than 1 million affected to the Department of Health and Human Services.
The First Enforcement Of The Notification Law
On March 13, 2012, HHS announced a $1.5 million settlement with the insurer and a corrective action plan. The agency said it was the first enforcement action to arise from a breach reported under the HITECH Act’s notification requirement, which had taken effect in September 2009, a matter of days before the theft. Investigators found the company had not performed a security evaluation after moving out of the facility and had not maintained adequate physical access controls.
The company put its own response cost at more than $7 million by February 2010 and about $17 million in total, according to contemporaneous reporting. The penalty was less than a tenth of what the breach had already cost.
A Recording Is A Record
The file is here because of what the data was. A call recording is the member’s own voice stating the fields an identity thief needs, with the diagnosis attached. It cannot be redacted after the fact and was never designed to be searched, which is why nobody had thought to encrypt it. The sector spent the following decade learning that the copy of the data nobody thinks of as a database is the copy that leaves.
Compiled from the HHS announcement and resolution agreement and from contemporaneous trade reporting, listed below. The count rose over time and is given at each stage with its source. No attribution exists; the theft was never solved in the material reviewed. Graded high. Corrections: corrections@forensicpost.com.
- HHS settles HIPAA case with BCBST for $1.5 millionU.S. Department of Health and Human Services
- BCBS Notifying 520,000 About BreachHealthcareInfoSecurity
- Tennessee insurer to pay $1.5 million for breach-related violationsComputerworld