Live data from Hacker News

“Anthem was the target of a very sophisticated external cyber attack”

anthemfacts.com

151–160 of 206 posts

Re: “Anthem was the target of a very sophisticated external cyber attack”

#151
post #36

Turned 26 in January. Purchased Anthem medical insurance so I don't get penalized by Obamacare. Surprised how expensive it is, but bit my tongue and continue. Anthem gets hacked. My Name + SSN is probably somewhere it shouldn't be; ugh.

You are required to give your SSN if accepting the Obamacare subsidy, look for it in the "fine print," which doesn't come close to meeting the intent of the Federal Privacy Act of 1974 (Public Law 93-579). Unfortunately, the Obamacare subsidy is a form of government assistance. The healthcare.gov operation is a joint venture between the government and non-government entities. If you are personally paying for your coverage, you "voluntarily" gave it to them when you filled out their application. I personally haven't been known to any insurance company, especially health and life, by my SSN since 1979! Remember, they can't lose (or be hacked out of) misplace, abuse or misuse what they don't have. All government agencies (but not anyone else) are required to follow the Federal Privacy Act of 1974 and it's requirements prior to you disclosing your SSN to them. Unless someone is paying you a salary, wages or interest don't give up your SSN! Don't ever give up your SSN and accept a lifetime of liability and potential ID theft for some else's 3 seconds of convenience. You are not numbered like a head of livestock. Stand your ground and take your business elsewhere when dealing with a non-government entity who insists on having your SSN! Information travels in one direction and you're not going to get it back.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#152
post #108

Why were they storing sensitive data of former customers? It seems like a risk with no benefit, with the only justification being "all data could be valuable eventually so let's never delete even the personal sensitive data." Ironically, the data did eventually become valuable - to someone else.

Proof of coverage can be important. It used to be common for insurance companies to look carefully at your coverage record, and if you had any time during which you were not covered, they'd say stuff like "Oh, that horrible cancer you have? Yeah, we're not paying for it because it was a 'pre-existing condition' that you got during that weekend you had between two jobs six years ago." And the law let them do that. Hea…

Kreig gegen den krankenvolk.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#153
post #63

Having spent almost 4 years in healthcare IT. Very few healthcare organizations take security seriously. There is very much a security by anonymity ideal. I worked for a small medical company that had access to 20,000 PHI records, and I was explicitedly told, "why would anyone want to hack us, we are small potatoes." I left that company shortly there after. Yet companies I work with now big and small look at security…

Exactly my experience. We had all the production passwords for servers and databases in a text file in the repository because the chief architect didn't like to remember passwords. When I pointed this out as a HIPAA violation the CTO told me they passed their audits so it didn't matter.

> When I pointed this out as a HIPAA violation

What provision of HIPAA does this actually violate?

Its clearly a bad practice (and obviously increase the risk of a breach, which, if it occurs, becomes an issue under HIPAA and related laws), but AFAIK neither HIPAA and subsequent modifying statutes nor the regulations adopted thereunder actually mandate particular password handling practices. Or is there something addressing that in the "guidance" issued under the HITECH act (I remember that establishing, by reference, some standards for encryption, and it wouldn't have been out of place for it to establish password-handling practices)?

Re: “Anthem was the target of a very sophisticated external cyber attack”

#154
post #124

Earlier quoted context omitted.

Well, somehow engineers and architects manage to resist management pressures in favor for security, you don't see many bridges collapsing but they have financial constraints too. And accountants resist management pressures to bend the accounting standard, or they go to prison too. IT is in many respect an unregulated profession. Pretty much anyone can declare himself a programmer. There are some regulations on certai…

There are certain regulations about IT, enforced not by the government but by private companies (such as PCI). I'm just going to have to disagree with you and move on about regulating the people, though. I see your point, but I just don't agree. If anything, I feel managers should be regulated, so they are only allowed to oversee positions where they have the knowledge to fully understand what their direct reports ar…

I am not saying that regulation is desirable. In fact it is going to be a major obstacle to innovation. What I am saying is that we pretty much see a major data breach every week. There are some instances where one can call them force majeure, like a zero day on a major security component in windows or linux. But there is no excuse for SQL injections vulnerabilities, unencrypted personal data, IT professionals logging-in to websites without checking the URL, unpatched systems, etc.

Complaining about budgets to fix these issues is like saying that the problems with collapsing bridges is that we don't spend enough fixing the structure. Well, it should have been built properly in the first place.

Yes, resources will have to be allocated to fix existing systems but I think the problem here is more fundamental than a problem of budget and management focus. We need to have a profession competent enough to build a bridge structurally sound even with average engineers.

And this is a general comment. We don't know yet how this particular breach happened.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#155
I've been with Anthem since going back to the UC system.

Is there any way to check if I'm affected by the breach? University of California has not made an official statement regarding the breach whatsoever.

I'm looking for something similar to the way you could enter your email address and figure out if your Adobe account was hacked.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#156
post #108

Why were they storing sensitive data of former customers? It seems like a risk with no benefit, with the only justification being "all data could be valuable eventually so let's never delete even the personal sensitive data." Ironically, the data did eventually become valuable - to someone else.

Proof of coverage can be important. It used to be common for insurance companies to look carefully at your coverage record, and if you had any time during which you were not covered, they'd say stuff like "Oh, that horrible cancer you have? Yeah, we're not paying for it because it was a 'pre-existing condition' that you got during that weekend you had between two jobs six years ago." And the law let them do that. Hea…

  > they'd say stuff like "Oh, that horrible cancer you have?
  > Yeah, we're not paying for it because it was a 'pre-
  > existing condition' that you got during that weekend you 
  > had between two jobs six years ago."
Can you give a link to an article about this? I didn't know "pre-existing condition" worked like that.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#157

Earlier quoted context omitted.

But it is private and it does unlock keys to lines of credit. It is not simply a "primary key" as stated, whether or not that was the original intent is not the argument here however. Recall the LifeLock CEO* plastered his SSN publicly and felt the repercussions. While I won't suggest you do that here - just knowing that if you did the assumption is bad things will happen in due time. Keeping SSNs private today is a…

I heard about that, but when you publicly tell a bunch of hackers "come at me bro", you have to expect that kind of reaction. But realistically, the cat is out of the bag with regards to SSNs. Legally you can obtain someone's SSN for very little money. If you go the illegal route, I'd be willing to bet that there is black-market identity data on over half of Americans. We really need to treat SSNs as about as secret…

> Legally you can obtain someone's SSN for very little money.

Not legally. You certainly can go onto a website and buy them, if you misrepresent your purposes, and you won't be caught... but it's still illegal.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#158

Earlier quoted context omitted.

Exactly my experience. We had all the production passwords for servers and databases in a text file in the repository because the chief architect didn't like to remember passwords. When I pointed this out as a HIPAA violation the CTO told me they passed their audits so it didn't matter.

> When I pointed this out as a HIPAA violation What provision of HIPAA does this actually violate? Its clearly a bad practice (and obviously increase the risk of a breach, which, if it occurs, becomes an issue under HIPAA and related laws), but AFAIK neither HIPAA and subsequent modifying statutes nor the regulations adopted thereunder actually mandate particular password handling practices. Or is there something add…

Covered entities must "[protect] against any reasonably anticipated threats or hazards to the security or integrity of such [electronic protected health information the covered entity creates, receives, maintains, or transmits]" (45 C.F.R. § 164.306(a), http://www.law.cornell.edu/cfr/text/45/164.306). Storing passwords in the clear "obviously increase [sic] the risk of a breach", hence this is a reasonably anticipated threat.

HIPAA and similar laws don't codify whatever we think is good computing practice today. Down that path lies madness. Congress would have to re-write the law any time GCPs change, or else the law would become a hindrance to the very goals its trying to achieve (in this case, healthcare-related information security). Instead, the law is written more generally, with "reasonable" being the keyword that lets the legal system refer to current practice.

(My adaptation of "GCP" is stolen shamelessly from the clinical research folks, who use it to refer to "good clinical practice", https://en.wikipedia.org/wiki/Good_clinical_practice.)

Re: “Anthem was the target of a very sophisticated external cyber attack”

#159

Earlier quoted context omitted.

Start with Trans Union, they have a child specific application so you can find out if your child's SSN has been used by identity thieves: http://www.transunion.com/corporate/personal/fraudIdentityTh... If they don't have any reports, there's a good chance you're probably ok. You can also apply to put a security freeze on your child's SSN. State by state laws and application process here: http://consumersunion.org/res…

Just filled out the Trans Union site with dummy data to check, and none of the transaction is over SSL. So, to kind out if my child's identity has been stolen I have to expose them to identity theft....

Wow. That is incredibly hilarious and sad. I passed the note on to TU.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#160
post #108

Why were they storing sensitive data of former customers? It seems like a risk with no benefit, with the only justification being "all data could be valuable eventually so let's never delete even the personal sensitive data." Ironically, the data did eventually become valuable - to someone else.

Proof of coverage can be important. It used to be common for insurance companies to look carefully at your coverage record, and if you had any time during which you were not covered, they'd say stuff like "Oh, that horrible cancer you have? Yeah, we're not paying for it because it was a 'pre-existing condition' that you got during that weekend you had between two jobs six years ago." And the law let them do that. Hea…

"And the law let them do that."

IIUC, not since Obamacare went into full effect in 2014. One of the main provisions of it was that it became illegal to deny coverage based on pre-existing conditions.

They still need the records because one of the other effects of Obamacare is that it became illegal to not have health insurance, but it's broken in a different way now.

Post reply on HN