DataBreaches.net

DataBreaches.net

The Office of Inadequate Security

Menu
  • Breach Laws
  • About
  • Donate
  • Contact
  • Privacy
  • Transparency Reports
Menu

Data breach affects almost 400,000 Community Health Plan members (UPDATE2)

Posted on December 21, 2016April 24, 2019 by Dissent

Bob Young reports:

Almost 400,000 current and former members of the Community Health Plan of Washington have had personal information, including Social Security numbers, exposed in a data breach.

The nonprofit, which provides health insurance through Medicaid in Washington, is sending letters to 381,534 individuals Wednesday notifying them of the invasion and steps they can take to protect themselves with help from Community Health Plan of Washington.

Read more on The Seattle Times. The incident appears to involve an unnamed business associate/vendor that is a subsidiary of NTT Data.

UPDATE: It appears that this breach is yet another caused by a public FTP server, and that it was discovered by a security researcher who reported it to them. Interesting that the reporting says “invasion,” and I’ll be interested to see how the covered entity explains this breach to its members. In the meantime, I’m changing the tags on this incident from “hack” to “exposure.”

UPDATE 2: And now we know the name of the BA: Transaction Applications Group Inc., doing business as NTT Data, who processes claims for CHPW. Read more on GovInfoSecurity. It sounds like CHPW may be building a case of hacking against the researcher.

Related Posts:

  • Social security numbers stolen from Tufts Health members
  • Kaiser notifies 8,000 members whose information was…
  • Geisinger Health Plan Notifies Members About…
  • Health insurers say data on 280,000 Pennsylvania…
  • Flash drive with Medicaid numbers missing

Post navigation

← Data Breach Plaintiffs’ Allegations Sufficient for Standing in Employee’s Suit Against CareCentrix
University of Nebraska-Lincoln notifies 30,000 of breach that may have occurred two years ago →

2 thoughts on “Data breach affects almost 400,000 Community Health Plan members (UPDATE2)”

  1. Anonymous says:
    December 28, 2016 at 5:43 pm

    CHPW blames NTT Data, a subsidiary of Nippon Telegraph and Telephone.
    CHPW says they reported breach to HHS.
    But wall of shame does not list it.
    Except that the Peachtree Orthopaedics breach has the same size and was reported a few days earlier.
    And newspaper accounts in Atlanta say that breach involved a ransom demand.

    But Justin S says he noticed the records were available to all in in unsecured anonymous FTP server.

    Was this an instance of careless, ransom, or state-sponsored? (Could be all three)

    Anyone know what gives here?

    1. Dissent says:
      December 28, 2016 at 5:57 pm

      1. HHS is often a tad slow in showing breach reports they’ve received – sometimes by weeks. Be patient, it will show up.
      2. Peachtree Orthopedics was reported to HHS on November 18, after they confirmed it 9/22. CHPW first learned of their breach on Nov. 7. They didn’t report it to HHS until around Dec. 18.
      3. There’s lots of coverage on my site about the Peachtree hack and ransom demands, beginning in August when I first suspected they were a victim. Media in Atlanta were slow to report what my readers knew months ago.
      4. The CHPW appears to be human error by the vendor/BA.

Comments are closed.

Sponsored or Paid Posts

This site doesn’t accept sponsored posts and doesn’t respond to requests about them.

Have a News Tip?

Email:

Breaches[at]Protonmail.ch
Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Telegram: @DissentDoe

Browse by News Section

Latest Posts

  • Update: Cardiovascular Consultants Ltd. ransomware attack reportedly affected 500,000 patients, guarantors, and staff
  • Data breach by Addenbrooke’s Hospital reveals patient information
  • Millions of patient scans and health records spilling online thanks to decades-old protocol bug
  • Cybersecurity: Federal Agencies Made Progress, but Need to Fully Implement Incident Response Requirements (GAO Report)
  • Hackers Exploited ColdFusion Vulnerability to Breach Federal Agency Servers
  • CBIZ KA Notice of Data Privacy Incident (Prime Healthcare)
  • Seeking clarification on Maine’s data breach notification statute
  • East River Medical Imaging notifies 605,809 patients of breach

Please Donate

If you can, please donate XMR to our Monero wallet because the entities whose breaches we expose are definitely not supporting our work and are generally trying to chill our speech!

Donate- Scan QR Code   Donate!

Social Media

Find me on Infosec.Exchange.

I am also on Telegram @DissentDoe.

RSS

Grab the RSS Feed

Copyright

© 2009 – 2023, DataBreaches.net and DataBreaches LLC. All rights reserved.

HIGH PRAISE, INDEED!

“You translate “Nerd” into understandable “English” — Victor Gevers of GDI Foundation, talking about DataBreaches.net

©2023 DataBreaches.net