Desk live·
ForensicPost
Insurance/Health/File 13-1206

Horizon BCBS of New Jersey Lost 839,711 Members’ Data on Two Laptops With the Cable Locks Cut

The MacBooks were taken from the eighth floor of the insurer’s Newark headquarters over a November weekend. They were password-protected and unencrypted. The state later alleged more than 100 such laptops were outside IT’s monitoring.

Constructed geometry · not a chart of case data
JurisdictionUSANewarkthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetHorizon Blue Cross Blue Shield of New Jersey
ActorUnattributed
D. Kennedy8 min readConfidence: high3 sources reviewed

Two Apple laptops were stolen from Horizon Blue Cross Blue Shield of New Jersey’s headquarters at 3 Penn Plaza in Newark over the weekend of Nov. 1 to 3, 2013. Staff found the cable locks cut on Monday, Nov. 4, and reported the theft to police. Letters to members went out around Dec. 6. The company said 839,711 people were affected. The laptops held names, addresses, birth dates and member identification numbers, and for some members Social Security numbers and limited clinical information.

The machines were password-protected. They were not encrypted. The distinction is the whole file.

A Hundred More Like Them

When New Jersey’s Division of Consumer Affairs settled with Horizon on Feb. 17, 2017, its allegations went beyond the two laptops. The state said more than 100 unencrypted laptops in the company were not being monitored by its IT department, so nobody could say what any of them held. The consent order required $1.1 million in penalties and costs, of which $926,803 was the civil penalty, plus three years of independent annual risk analyses.

The Standing Case That Went The Other Way

The members’ class action was dismissed in 2015 for lack of injury. The Third Circuit revived it on Jan. 20, 2017, holding that the unauthorised disclosure of personal information under the Fair Credit Reporting Act was itself a concrete harm. Six months later the D.C. Circuit reached a similar result in the CareFirst case filed at 15-0520. The Horizon case was dismissed again in December 2021 with leave to amend, and its final disposition was not established.

Encryption As The Only Control That Mattered

A laptop will be stolen. The only question a regulator asks afterwards is whether the disk was encrypted, because that is the difference between a lost asset and a breach of 839,711 people. Horizon had the password and not the encryption, and the file exists because of that gap.

How we reported this

Compiled from the New Jersey attorney general’s 2017 release, the Third Circuit’s opinion and contemporaneous reporting, listed below. The member count is the company’s. The settlement figure is $1.1 million in total; earlier reporting sometimes confused it with the member count. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Horizon Blue Cross Blue Shield settlement, Feb. 17, 2017New Jersey Attorney General
  2. Horizon Policyholders Warned Of Possible Identity Theft From Stolen LaptopsCBS New York
  3. In re Horizon Healthcare Services Inc. Data Breach Litigation, No. 15-2309U.S. Court of Appeals for the Third Circuit
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary