Turned 26 in January. Purchased Anthem medical insurance so I don't get penalized by Obamacare. Surprised how expensive it is, but bit my tongue and continue. Anthem gets hacked. My Name + SSN is probably somewhere it shouldn't be; ugh.
“Anthem was the target of a very sophisticated external cyber attack”
151–160 of 206 posts
Re: “Anthem was the target of a very sophisticated external cyber attack”
#152Why were they storing sensitive data of former customers? It seems like a risk with no benefit, with the only justification being "all data could be valuable eventually so let's never delete even the personal sensitive data." Ironically, the data did eventually become valuable - to someone else.
Proof of coverage can be important. It used to be common for insurance companies to look carefully at your coverage record, and if you had any time during which you were not covered, they'd say stuff like "Oh, that horrible cancer you have? Yeah, we're not paying for it because it was a 'pre-existing condition' that you got during that weekend you had between two jobs six years ago." And the law let them do that. Hea…
Re: “Anthem was the target of a very sophisticated external cyber attack”
#153Having spent almost 4 years in healthcare IT. Very few healthcare organizations take security seriously. There is very much a security by anonymity ideal. I worked for a small medical company that had access to 20,000 PHI records, and I was explicitedly told, "why would anyone want to hack us, we are small potatoes." I left that company shortly there after. Yet companies I work with now big and small look at security…
Exactly my experience. We had all the production passwords for servers and databases in a text file in the repository because the chief architect didn't like to remember passwords. When I pointed this out as a HIPAA violation the CTO told me they passed their audits so it didn't matter.
What provision of HIPAA does this actually violate?
Its clearly a bad practice (and obviously increase the risk of a breach, which, if it occurs, becomes an issue under HIPAA and related laws), but AFAIK neither HIPAA and subsequent modifying statutes nor the regulations adopted thereunder actually mandate particular password handling practices. Or is there something addressing that in the "guidance" issued under the HITECH act (I remember that establishing, by reference, some standards for encryption, and it wouldn't have been out of place for it to establish password-handling practices)?
Re: “Anthem was the target of a very sophisticated external cyber attack”
#154Earlier quoted context omitted.
Well, somehow engineers and architects manage to resist management pressures in favor for security, you don't see many bridges collapsing but they have financial constraints too. And accountants resist management pressures to bend the accounting standard, or they go to prison too. IT is in many respect an unregulated profession. Pretty much anyone can declare himself a programmer. There are some regulations on certai…
There are certain regulations about IT, enforced not by the government but by private companies (such as PCI). I'm just going to have to disagree with you and move on about regulating the people, though. I see your point, but I just don't agree. If anything, I feel managers should be regulated, so they are only allowed to oversee positions where they have the knowledge to fully understand what their direct reports ar…
Complaining about budgets to fix these issues is like saying that the problems with collapsing bridges is that we don't spend enough fixing the structure. Well, it should have been built properly in the first place.
Yes, resources will have to be allocated to fix existing systems but I think the problem here is more fundamental than a problem of budget and management focus. We need to have a profession competent enough to build a bridge structurally sound even with average engineers.
And this is a general comment. We don't know yet how this particular breach happened.
Re: “Anthem was the target of a very sophisticated external cyber attack”
#155Is there any way to check if I'm affected by the breach? University of California has not made an official statement regarding the breach whatsoever.
I'm looking for something similar to the way you could enter your email address and figure out if your Adobe account was hacked.
Re: “Anthem was the target of a very sophisticated external cyber attack”
#156Why were they storing sensitive data of former customers? It seems like a risk with no benefit, with the only justification being "all data could be valuable eventually so let's never delete even the personal sensitive data." Ironically, the data did eventually become valuable - to someone else.
Proof of coverage can be important. It used to be common for insurance companies to look carefully at your coverage record, and if you had any time during which you were not covered, they'd say stuff like "Oh, that horrible cancer you have? Yeah, we're not paying for it because it was a 'pre-existing condition' that you got during that weekend you had between two jobs six years ago." And the law let them do that. Hea…
> they'd say stuff like "Oh, that horrible cancer you have?
> Yeah, we're not paying for it because it was a 'pre-
> existing condition' that you got during that weekend you
> had between two jobs six years ago."
Can you give a link to an article about this? I didn't know "pre-existing condition" worked like that.Re: “Anthem was the target of a very sophisticated external cyber attack”
#157Earlier quoted context omitted.
But it is private and it does unlock keys to lines of credit. It is not simply a "primary key" as stated, whether or not that was the original intent is not the argument here however. Recall the LifeLock CEO* plastered his SSN publicly and felt the repercussions. While I won't suggest you do that here - just knowing that if you did the assumption is bad things will happen in due time. Keeping SSNs private today is a…
I heard about that, but when you publicly tell a bunch of hackers "come at me bro", you have to expect that kind of reaction. But realistically, the cat is out of the bag with regards to SSNs. Legally you can obtain someone's SSN for very little money. If you go the illegal route, I'd be willing to bet that there is black-market identity data on over half of Americans. We really need to treat SSNs as about as secret…
Not legally. You certainly can go onto a website and buy them, if you misrepresent your purposes, and you won't be caught... but it's still illegal.
Re: “Anthem was the target of a very sophisticated external cyber attack”
#158Earlier quoted context omitted.
Exactly my experience. We had all the production passwords for servers and databases in a text file in the repository because the chief architect didn't like to remember passwords. When I pointed this out as a HIPAA violation the CTO told me they passed their audits so it didn't matter.
> When I pointed this out as a HIPAA violation What provision of HIPAA does this actually violate? Its clearly a bad practice (and obviously increase the risk of a breach, which, if it occurs, becomes an issue under HIPAA and related laws), but AFAIK neither HIPAA and subsequent modifying statutes nor the regulations adopted thereunder actually mandate particular password handling practices. Or is there something add…
HIPAA and similar laws don't codify whatever we think is good computing practice today. Down that path lies madness. Congress would have to re-write the law any time GCPs change, or else the law would become a hindrance to the very goals its trying to achieve (in this case, healthcare-related information security). Instead, the law is written more generally, with "reasonable" being the keyword that lets the legal system refer to current practice.
(My adaptation of "GCP" is stolen shamelessly from the clinical research folks, who use it to refer to "good clinical practice", https://en.wikipedia.org/wiki/Good_clinical_practice.)
Re: “Anthem was the target of a very sophisticated external cyber attack”
#159Earlier quoted context omitted.
Start with Trans Union, they have a child specific application so you can find out if your child's SSN has been used by identity thieves: http://www.transunion.com/corporate/personal/fraudIdentityTh... If they don't have any reports, there's a good chance you're probably ok. You can also apply to put a security freeze on your child's SSN. State by state laws and application process here: http://consumersunion.org/res…
Just filled out the Trans Union site with dummy data to check, and none of the transaction is over SSL. So, to kind out if my child's identity has been stolen I have to expose them to identity theft....
Re: “Anthem was the target of a very sophisticated external cyber attack”
#160Why were they storing sensitive data of former customers? It seems like a risk with no benefit, with the only justification being "all data could be valuable eventually so let's never delete even the personal sensitive data." Ironically, the data did eventually become valuable - to someone else.
Proof of coverage can be important. It used to be common for insurance companies to look carefully at your coverage record, and if you had any time during which you were not covered, they'd say stuff like "Oh, that horrible cancer you have? Yeah, we're not paying for it because it was a 'pre-existing condition' that you got during that weekend you had between two jobs six years ago." And the law let them do that. Hea…
IIUC, not since Obamacare went into full effect in 2014. One of the main provisions of it was that it became illegal to deny coverage based on pre-existing conditions.
They still need the records because one of the other effects of Obamacare is that it became illegal to not have health insurance, but it's broken in a different way now.