Desk live·
ForensicPost
Insurance/Health/File 11-0314

Health Net Could Not Account for Nine Server Drives Holding 1.9 Million Members’ Records

IBM, which ran the insurer’s California data centre, reported the drives missing after a migration in January 2011. Six were never found. Nobody established whether they were stolen, and the case closed with credit monitoring, a $200,000 state penalty and no cash for members.

Constructed geometry · not a chart of case data
JurisdictionUSAWoodland Hillsthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetHealth Net
ActorUnattributed
D. Kennedy8 min readConfidence: high4 sources reviewed

On Jan. 21, 2011, IBM told Health Net that it could not locate nine server drives after a data migration at the Rancho Cordova, California, data centre it operated for the insurer. Health Net announced the loss on March 14, 2011, and began notifying about 1.9 million current and former members. The drives held names, addresses, Social Security numbers, financial information and health data.

Three of the drives were later found by IBM, according to the California Department of Managed Health Care. Six remained unaccounted for. No theft was ever confirmed and no one was charged.

Lost, Not Stolen, And Not Much Different

The distinction between a drive that was taken and a drive that cannot be found is meaningful to investigators and meaningless to members. In either case the data is outside the organisation’s control and the record cannot say where. The corpus files the physical-media era of the sector, from the Tennessee drives at 09-1002 to the New Jersey laptops at 13-1206, as one shape: identity data on hardware that was never inventoried closely enough to notice its absence quickly.

Six Investigations, One Small Penalty

Health Net told the Securities and Exchange Commission that the incident drew inquiries from the California Department of Managed Health Care, the California Department of Insurance, the California attorney general, the Connecticut attorney general, the Connecticut Department of Insurance and the federal health department. The one monetary outcome found is a $200,000 settlement with the managed-care regulator.

A federal class action was dismissed in January 2012 for lack of standing. A state case in Sacramento settled with final approval in June 2014: two years of credit monitoring, identity theft insurance and reimbursement of documented losses up to $50,000. No cash fund was created. Health Net had already paid Connecticut $250,000 in 2010 over a separate lost drive from 2009.

How we reported this

Compiled from Health Net’s SEC filings, the Connecticut attorney general’s 2011 release and contemporaneous trade reporting, listed below. The 1.9 million figure is the state regulator’s; the company said approximately 2 million. The $200,000 penalty appears in a regulator document that could not be fetched directly and is stated as reported. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Health Net, Inc., Form 10-Q for the quarter ended March 31, 2012U.S. Securities and Exchange Commission
  2. Attorney General statement on Health Net breach, March 14, 2011Connecticut Attorney General
  3. Health Net Breach Affects 1.9 MillionHealthcareInfoSecurity
  4. Health Net Investigating Unaccounted-for Server DrivesBusiness Wire
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary