Live data from Hacker News

“Anthem was the target of a very sophisticated external cyber attack”

anthemfacts.com

161–170 of 206 posts

Re: “Anthem was the target of a very sophisticated external cyber attack”

#161

Earlier quoted context omitted.

> When I pointed this out as a HIPAA violation What provision of HIPAA does this actually violate? Its clearly a bad practice (and obviously increase the risk of a breach, which, if it occurs, becomes an issue under HIPAA and related laws), but AFAIK neither HIPAA and subsequent modifying statutes nor the regulations adopted thereunder actually mandate particular password handling practices. Or is there something add…

Covered entities must "[protect] against any reasonably anticipated threats or hazards to the security or integrity of such [electronic protected health information the covered entity creates, receives, maintains, or transmits]" (45 C.F.R. § 164.306(a), http://www.law.cornell.edu/cfr/text/45/164.306 ). Storing passwords in the clear "obviously increase [sic] the risk of a breach", hence this is a reasonably anticipat…

> Covered entities must "[protect] against any reasonably anticipated threats or hazards to the security or integrity of such [electronic protected health information the covered entity creates, receives, maintains, or transmits]" (45 C.F.R. § 164.306(a), http://www.law.cornell.edu/cfr/text/45/164.306).

But they also have freedom to select the particular security measures to use, considering: "(i) The size, complexity, and capabilities of the covered entity. (ii) The covered entity's technical infrastructure, hardware, and software security capabilities. (iii) The costs of security measures. (iv) The probability and criticality of potential risks to electronic protected health information." 45 C.F.R. § 164.306(b)

> HIPAA and similar laws don't codify whatever we think is good computing practice today.

No, but that's what implementing regulations usually do. HIPAA regs mostly don't include minimum technical standards (most of the security minimum standards are procedural).

> Congress would have to re-write the law any time GCPs change

Well, sure, if the minimum standards were written into the statute, which is why they are usually in the much-easier-to-change implementing regulations. The guidance under the HITECH act in effect did some of this for HIPAA PHI, as it created minimum standards for PHI to be considered "secured". But, generally, there's not much there, and its very difficult to make a solid case that any particular technical practice is necessarily a violation of the HIPAA Security Rule.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#162
post #154

Earlier quoted context omitted.

There are certain regulations about IT, enforced not by the government but by private companies (such as PCI). I'm just going to have to disagree with you and move on about regulating the people, though. I see your point, but I just don't agree. If anything, I feel managers should be regulated, so they are only allowed to oversee positions where they have the knowledge to fully understand what their direct reports ar…

I am not saying that regulation is desirable. In fact it is going to be a major obstacle to innovation. What I am saying is that we pretty much see a major data breach every week. There are some instances where one can call them force majeure, like a zero day on a major security component in windows or linux. But there is no excuse for SQL injections vulnerabilities, unencrypted personal data, IT professionals loggin…

"Complaining about budgets to fix these issues is like saying that the problems with collapsing bridges is that we don't spend enough fixing the structure. Well, it should have been built properly in the first place."

I'd like to think that engineers do want to build things properly, however to build something properly it usually involves more resources. The problem is when it comes down to brass tax the low bidder wins. I've worked in many big companies over many years, and yes I've hacked things together MANY times because of budget/time constraints. A lot of it was because of Management wanting to come under budget, or because they wanted to rush the product to be a hero.

I don't get where this idea comes from that engineers just want to do things in the worst way, do you think a doctor wants to kill his patients or do something that would endanger the patient if they didn't have to?

Re: “Anthem was the target of a very sophisticated external cyber attack”

#163
post #127

Earlier quoted context omitted.

At 26, quite possibly.

Yeah, cause accidents don't happen in your 20s.

True, but young people use very little coverage (less than they pay for) on average. They are subsidizing the plans of older people.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#164
post #71

I'm just thrilled to recently be downgraded to an Anthem customer. I miss my old insurance.

They're fantastically better than any other insurance I've had. What they cover for my family is easily another income every year. What did you have before?

Anthem is very schizophrenic about their group vs. individual plans. I was covered by them under Google's group plan and they were easily the best insurance company I've had. They paid for all sorts of things that other insurers wouldn't bother for, no questions asked, and were great to deal with.

Then I tried continuing with one of their individual plans after leaving, and they were easily the worst insurer I've ever dealt with. Things like not informing me that my PCP (who'd certainly been part of the group plan) was not part of the individual plan's network, or finding out that the nearest available PCP who was is 40 miles away (I live in a major metropolitan area with several million inhabitants). Not being able to change my address through the website - they have a form up that doesn't work, along with a message saying "If this form doesn't work, please call ..." Taking hours to get ahold of a human on the phone. Billing hassles. Sending out "your coverage is ending in 30 days because of non-payment" notices even though I'd faithfully paid online on-time. I'm actually quite glad that their terms are "Your policy ends automatically when you don't pay", because they've made it pretty much impossible for me to pay them - their online billpay refuses to take my payment (failing with no error message), which I suspect is because my address changed, but their website makes it impossible for me to update my address, calling them takes more time than I'm willing to invest, and I don't have any trust that if I send them a check it will actually be credited to my account. I just started a policy with Blue Cross Blue Shield instead, which has been a joy in comparison, and let Anthem lapse.

If you read the Yelp reviews, they're far worse than my situation - folks being promised coverage for hospital stays and then denied coverage afterwards, and multiple lawsuits outstanding against them.

The cynic in me thinks that Anthem is basically unable to continue as an operating business, and so they're triaging accounts. The big group accounts like Google get top-of-the-line service, so that they can keep them and hopefully bring in enough revenue to tide the company over. The individual accounts - anything that's small enough to (presumably) not have many other options and unable to sue - get screwed. So if you're in one of those groups, be thankful; if you're an individual, start looking elsewhere.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#165
post #121

I feel most for those who have young children. If you consider the long term viability of SSN over the life-span of a person who is under the age of 5 today they'll likely have been exposed to a breach that will contain their dox a few times over by the time they reach a legal age - that is likely a conservative estimate given the frequency of these events. SSN is broken and we're going to see a lot of push back goin…

If you live in California, you have the right to put a security freeze on your child's credit file. This will prevent one of the most serious types of identity theft with a stolen SSN. Other states might have similar laws. http://oag.ca.gov/idtheft/facts/freeze-your-credit

It is not possible to put a freeze on a child's SSN until they have a credit file. So unless they have been a victim of an identity theft or have a credit file (because they have a credit card from their parent for eg) this won't work. The only thing to do for parents with minor children is to monitor their SSN for activity.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#166
This is a big company, publicly embarrassed by a breach in data security and worried about their stock price. Now they're in damage control mode.

Call me a cynic, but my intuition says the whole page is a lie. My guess is the data was simply pilfered and copied to a USB stick by a disgruntled ex-employee or even a corruptible current one.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#167
I wonder why they needed to store SSNs online. They use SSNs to run a credit check and identity a person. Why then is it not stored encrypted and over an air gap? They can use email and phone numbers to recover passwords. This is absolutely ridiculous.

They said in an email that they would pay for one year of credit protection for all those that they say were victimized. I don't think that they are capable or trustworthy enough to state who was victimized. It looks to me that they are just ignoring their responsibility for this attack. They also stated that they do not think health records have been compromised. I believe that they are just trying to avoid HIPAA fees. If so much personal data was stolen, it is likely that health information was also stolen. Generally, the patient's personally identifiable information is stored more securely than their actual health record.

Now I'm off to get credit protection for me, my wife, and my one year old. Does anyone have any advice on where to begin?

Re: “Anthem was the target of a very sophisticated external cyber attack”

#169
post #124

Earlier quoted context omitted.

That's just not true. The direction of IT certainly is set by upper management, as well as the budget. If IT says 'we need an IDS' and management says 'it's not in the budget', what can IT do about it? If IT says 'it will take this long and this much money to change our password policy' and management say 'work on new things, not changing old things', what can IT do about it? Senior management might not directly set…

Well, somehow engineers and architects manage to resist management pressures in favor for security, you don't see many bridges collapsing but they have financial constraints too. And accountants resist management pressures to bend the accounting standard, or they go to prison too. IT is in many respect an unregulated profession. Pretty much anyone can declare himself a programmer. There are some regulations on certai…

> Well, somehow engineers and architects manage to resist management pressures in favor for security

When this does happen, it's often because management's "security" request is either nonsensical--based on some puff piece they saw in an airport magazine--or they won't accept the necessary financial-costs/organizational-changes of doing it right.

It's no coincidence that the people with the most exemptions from security policy are usually the upper management.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#170

Earlier quoted context omitted.

To be fair, if your systems relied on your chief architect not being hit by a bus, that would probably be worse than having the passwords stored someplace.

In reality he always played the "hero" as the only person who could fix the primary system, only because he built it so terribly in the first place.

Oh Christ I'll buy you a beer if we ever meet. Preach it.
Post reply on HN