Between Oct. 23, 2009, and March 7, 2010, an online application tracker run by WellPoint, then the largest U.S. health insurer by membership, allowed individual insurance applications to be viewed without proper authentication. The applications held names, addresses, Social Security numbers, financial details and health information. The Department of Health and Human Services put the affected population at 612,402.
The weakness was introduced by a software upgrade to the system’s authentication. A consumer notified WellPoint on Feb. 22, 2010, and again on March 8. The company secured the site after the second notice and began notifying applicants on June 18, 2010.
The Fix That Was Never Checked
HHS found three failures when it announced a $1.7 million settlement on July 11, 2013: no adequate policies for authorising access, no technical evaluation after the upgrade and no safeguards to verify who was requesting a record. The company had called the exposure human error. The regulator’s finding was narrower and more useful: a change was made to an authentication layer and nobody tested it.
A State Penalty For The Silence
Indiana’s attorney general sued in late 2010, not over the exposure but over the delay in reporting it. The state said WellPoint had known since February and told nobody until June. The July 2011 settlement paid $100,000 to a consumer fund and offered two years of credit monitoring. WellPoint admitted the notification failure.
The two actions describe the two halves of the sector’s obligation. One regulator penalised the control that failed. The other penalised the months in which applicants could have protected themselves and were not told they needed to.
Compiled from the HHS resolution agreement and reporting of the Indiana action, listed below. The 612,402 figure is the federal regulator’s; earlier state figures were lower and are not used. No attacker is alleged; this was an exposure. Graded high. Corrections: corrections@forensicpost.com.
- WellPoint Resolution AgreementU.S. Department of Health and Human Services
- Wellpoint Agrees to $1.7 Million Settlement for HIPAA ViolationsHIPAA Journal
- WellPoint Settles Over Data BreachInfoRiskToday