On Jan. 21, 2011, IBM told Health Net that it could not locate nine server drives after a data migration at the Rancho Cordova, California, data centre it operated for the insurer. Health Net announced the loss on March 14, 2011, and began notifying about 1.9 million current and former members. The drives held names, addresses, Social Security numbers, financial information and health data.
Three of the drives were later found by IBM, according to the California Department of Managed Health Care. Six remained unaccounted for. No theft was ever confirmed and no one was charged.
Lost, Not Stolen, And Not Much Different
The distinction between a drive that was taken and a drive that cannot be found is meaningful to investigators and meaningless to members. In either case the data is outside the organisation’s control and the record cannot say where. The corpus files the physical-media era of the sector, from the Tennessee drives at 09-1002 to the New Jersey laptops at 13-1206, as one shape: identity data on hardware that was never inventoried closely enough to notice its absence quickly.
Six Investigations, One Small Penalty
Health Net told the Securities and Exchange Commission that the incident drew inquiries from the California Department of Managed Health Care, the California Department of Insurance, the California attorney general, the Connecticut attorney general, the Connecticut Department of Insurance and the federal health department. The one monetary outcome found is a $200,000 settlement with the managed-care regulator.
A federal class action was dismissed in January 2012 for lack of standing. A state case in Sacramento settled with final approval in June 2014: two years of credit monitoring, identity theft insurance and reimbursement of documented losses up to $50,000. No cash fund was created. Health Net had already paid Connecticut $250,000 in 2010 over a separate lost drive from 2009.
Compiled from Health Net’s SEC filings, the Connecticut attorney general’s 2011 release and contemporaneous trade reporting, listed below. The 1.9 million figure is the state regulator’s; the company said approximately 2 million. The $200,000 penalty appears in a regulator document that could not be fetched directly and is stated as reported. Graded high. Corrections: corrections@forensicpost.com.
- Health Net, Inc., Form 10-Q for the quarter ended March 31, 2012U.S. Securities and Exchange Commission
- Attorney General statement on Health Net breach, March 14, 2011Connecticut Attorney General
- Health Net Breach Affects 1.9 MillionHealthcareInfoSecurity
- Health Net Investigating Unaccounted-for Server DrivesBusiness Wire