I miss my old insurance.
“Anthem was the target of a very sophisticated external cyber attack”
71–80 of 206 posts
Re: “Anthem was the target of a very sophisticated external cyber attack”
#72Having spent almost 4 years in healthcare IT. Very few healthcare organizations take security seriously. There is very much a security by anonymity ideal. I worked for a small medical company that had access to 20,000 PHI records, and I was explicitedly told, "why would anyone want to hack us, we are small potatoes." I left that company shortly there after. Yet companies I work with now big and small look at security…
I can only imagine the data protection standards at small equipment manufacturers and old-school pharmacies. I'd guess their biggest security measure is keeping paper files in a locked office.
Re: “Anthem was the target of a very sophisticated external cyber attack”
#73Earlier quoted context omitted.
Dox -> documents -> publishing personal information, no? Why does the victim have to be anonymous?
In modern usage of the term they don't. The term originated in underground circles where anonymity by all participants was assumed, and where there were probably legal or criminal revenge consequences for tying a pseudonym to a real identity. Kind of like how troll now means 'person who is an asshole on the internet' instead of 'post designed to rile up and elicit frivolous responses'. The meaning has changed over ti…
http://en.wikipedia.org/wiki/Doxing
And didn't the GGers "dox" Randi, Anita, Brianna, etc?
But I'm even more old school because I'd just call it skiptracing instead of doxing....
Re: “Anthem was the target of a very sophisticated external cyber attack”
#74Greeeeeeeeat. Anthem just became my health care provider. This fills me with confidence. I'm especially unimpressed by Anthem's failure to hire a good copy editor for such a vital message, as evidenced by the painfully obvious error at the end of the penultimate paragraph: "share that information you" should read "share that information with you".
Re: “Anthem was the target of a very sophisticated external cyber attack”
#75Earlier quoted context omitted.
A domain name that is being used exclusively to address to data breach, and was registered within the past 2 months. And it's just a coincidence? Seems very unlikely. And I'm sure they're quarantining negative info on an unrelated domain, but why would they even need to consider repurposing an existing domain name, instead of buying one? We're not talking about somebody doing a side project and hoping to save a few b…
What's unlikely about it? Maybe if the domain name was "anthemdatabreachinfo.com" or something more specific, but "anthemfacts.com"? Many companies register lots of variation of domain names that they aren't using. I don't think it's unlikely at all that this came up, and there was a meeting where they said "OK, do we have any existing domain names we can use for this?"
The website itself says "we have created a dedicated website ... anthemfacts.com" for this incident.
[Edit: replaced two egregious uses of "website" with "domain"]
Re: “Anthem was the target of a very sophisticated external cyber attack”
#76Earlier quoted context omitted.
Who cares about credit card numbers when you are protected for free and your credit card can be reissued unlike your SSN. I can't believe than in 2015 there's no modern way to verify and protect your identity! There are still so many stupid system relying on your last 4 of your SSN or DoB as authentication!
In Sweden we have a personal number. It's unique to every person but its not secret at all. You use an official identity card or passport or the electronic variant to identify yourself. I'm guessing its some kind of privacy issue behind there not being a similar system in US? Because it works pretty well.
Re: “Anthem was the target of a very sophisticated external cyber attack”
#77Earlier quoted context omitted.
In modern usage of the term they don't. The term originated in underground circles where anonymity by all participants was assumed, and where there were probably legal or criminal revenge consequences for tying a pseudonym to a real identity. Kind of like how troll now means 'person who is an asshole on the internet' instead of 'post designed to rile up and elicit frivolous responses'. The meaning has changed over ti…
I don't know, even Wikipedia seems to agree with me. http://en.wikipedia.org/wiki/Doxing And didn't the GGers "dox" Randi, Anita, Brianna, etc? But I'm even more old school because I'd just call it skiptracing instead of doxing....
Essentially, doxing is revealing and releasing records of an individual, which were previously private, to the public.
Where's the "reveal" in this hack? They'll use the hacked info privately or sell it.
Re: “Anthem was the target of a very sophisticated external cyber attack”
#78Looks like they misled the New York Times: http://www.nytimes.com/2015/02/05/business/hackers-breached-... > Anthem learned of the hacking last week and called in Mandiant over the weekend. The company was not obligated to report the breach for at least several more weeks but chose to do so now to show that it was treating the matter seriously. As user jakejohns has pointed out ( https://news.ycombinator.com/item?id=…
Could this be any more patronizing and offensive? Look, if you are Anthem member, or if you were an Anthem member, you've been doxxed... and quite comprehensively: have obtained personal information from our current and former members such as their names, birthdays, medical IDs/social security numbers, street addresses, email addresses and employment information, including income data And you were doxxed nearly two m…
Re: “Anthem was the target of a very sophisticated external cyber attack”
#79Earlier quoted context omitted.
> Why does Anthem know your income? It doesn't seem relevant to offer you health insurance products. Your income is strongly correlated with your health. The lower your income the more likely you are to suffer from conditions such as obesity and diabetes, and the higher your mortality rate will be. Health insurers can use income figures as one factor when calculating the overall risk of a policy.
Can you lie to them about it? Do they (or any insurance) actually verify your income?
It's not illegal, but it violates the contract you sign with them and lets them off the hook for paying for things. Mind you, they'll still keep the money you paid them.
Re: “Anthem was the target of a very sophisticated external cyber attack”
#80Looks like they misled the New York Times: http://www.nytimes.com/2015/02/05/business/hackers-breached-... > Anthem learned of the hacking last week and called in Mandiant over the weekend. The company was not obligated to report the breach for at least several more weeks but chose to do so now to show that it was treating the matter seriously. As user jakejohns has pointed out ( https://news.ycombinator.com/item?id=…
Could this be any more patronizing and offensive? Look, if you are Anthem member, or if you were an Anthem member, you've been doxxed... and quite comprehensively: have obtained personal information from our current and former members such as their names, birthdays, medical IDs/social security numbers, street addresses, email addresses and employment information, including income data And you were doxxed nearly two m…