BreachExchange mailing list archives

Re: Blue Cross Blue Shield of TN data breach


From: Henry Brown <hbrown () knology net>
Date: Thu, 28 Jan 2010 07:50:57 -0600

Followup story with significant more details from Chattanooga Times Free 
Press
http://bit.ly/8vd4sd

What was initially assumed to be just a glitch in some 
soon-to-be-discarded computer equipment last fall has grown into one of 
Chattanooga's most expensive property crimes of the year.

BlueCross BlueShield of Tennessee said Monday it already has spent more 
than $7 million to respond to the theft last October of computer hard 
drives from an abandoned office at Eastgate Center.

Although the Chattanooga-based health insurer has adequate reserves to 
absorb such losses, officials said the company may have to spend 
millions more to assess what was on the missing computer records and to 
provide identity protection for affected customers.

The missing computer files contained audio copies of telephone calls and 
records of video screen images that could compromise the identity or 
privacy of up to 500,000 Americans, company officials said.

BlueCross already has notified 220,000 BlueCross customers in Tennessee 
and other states where persons covered by BlueCross of Tennessee plans 
may work.

...

Determining what was on the 57 stolen computer hard drives  and 
complying with federal and state notification requirements already has 
required the hiring of more than 700 contract and BlueCross workers to 
assess back-up copies of the missing records.

...

-------- Original Message --------
Subject: [Dataloss-discuss] Blue Cross Blue Shield of TN data breach
From: Henry Brown <hbrown () knology net>
To: dataloss-discuss datalossdb.org <dataloss-discuss () datalossdb org>
Date: 1/11/2010 5:21 AM
   From Knoxville News:

http://tinyurl.com/ycvm8bh

January 10, 2010 at 9:41 p.m.

CHATTANOOGA - Customers of Chattanooga-based insurer BlueCross
BlueShield of Tennessee slowly are being notified by mail of a potential
breach of their personal information.
   
...

_______________________________________________
Dataloss-discuss Mailing List (dataloss-discuss () datalossdb org)
Archived at http://seclists.org/dataloss/

Get business, compliance, IT and security staff on the same page with
CREDANT Technologies: The Shortcut Guide to Understanding Data Protection
from Four Critical Perspectives. The eBook begins with considerations
important to executives and business leaders.
http://www.credant.com/campaigns/ebook-chpt-one-web.php


Current thread: