Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Premera Breach Emphasizes Risk to Holders of Medical Records and the Importance of Network Security
Articles

Premera Breach Emphasizes Risk to Holders of Medical Records and the Importance of Network Security

ISBuzz TeamBy ISBuzz TeamMarch 27, 2015Updated:May 8, 20155 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Premera Breach
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The recently announced breach of Premera, following so closely on the heels of Anthem, should set off alarm bells to other organizations in the healthcare industry, as it is an unfortunate likelihood that we will soon hear of other compromised healthcare companies. In both of these cases, the actual breach took place long before it was discovered, meaning every other healthcare company should be actively working to ensure their network is secure.

This attack on Premera’s health insurance data has been identified as the second-largest on record with about 11 million customers, employees and more affected, dating back to 2002. In February, Anthem’s system was hacked, resulting in information theft from around 80 million current and former customers.

While the Anthem breach was much larger in terms of the total number of records, the Premera Blue Cross breach is believed to include medical records along with personally identifiable information (PII), which could unlock the potential for significant medical fraud.  If insurance plan information is stolen along with identity information, data thieves would have a good indicator on which identities hold a higher value, based on the value of the insurance plan.  If thieves focus on the individuals with the highest plan costs, these are likely to be people who are more established in their lives, have families, higher incomes and better credit, meaning their identities are worth even more on the black market.

In addition, with the full medical records, someone who is committing ID fraud can target known issues with unscrupulous doctors and submit logical, albeit fraudulent claims. Imagine if a cancer patient’s records were stolen, for example, and the thief had enough information to pose as that individual. They could then work with a corrupt medical practice and submit reimbursement for expensive chemo therapy session claims (which are never actually provided). Since the real patient is a known cancer patient, this might not even set off any audit flags.  This is just one example in which medical fraud could occur.

This breach again calls into focus the reality that data security is not limited to the processing of payments and credit cards.  The same day that Premera publicly announced its breach, a relatively small dental company in Oregon announced it was also breached, and over 150,000 names and social security numbers and other PII was stolen.  Compared to Anthem or Premera, this breach seems minor, but it highlights the vast sources of data hackers have to choose from. Businesses of all kinds and across all industries must act to protect sensitive information stored in their systems.

The problem is data security is boring and tedious, making it easy to become the task we push off until tomorrow, and the next day, and the next day. There needs to be a broad understanding that in order to be truly protected, enterprises must become proactive in securing network access, encrypting data and auditing security methods on a regular basis.  While larger enterprises are potentially targets for highly sophisticated attacks, it is often the simple things that get missed. Being sure that every system has updated security patches, configurations are kept current, passwords are changed often and not used on two different systems and that two factor authentication is used were all possible in the cases of the breaches and are reasonable suggestions for companies of all sizes.

For larger enterprises, it means IT security professionals need to go back to basics every once in a while.  Employees at large companies can easily become complacent, relying on their big IT budgets to cover their basic IT security miscues.  This culture of complacency needs to be actively addressed by the IT security team, even if it means being the bad guys.

For smaller companies that don’t have the IT budget or staff, like the dental practice company, it means picking the right IT security partners.  For less than the cost of one filling per month, that dental company could have used a third-party IT security firm to protect their data.  A fully managed network security program will include not only remote firewall management but also systems to ensure configurations are consistently updated and security patches implemented.  Further, properly configured firewalls can ensure that if malware does find its way onto a network, the data on that network cannot be transmitted to an unauthorized location.

After the fact, audits of breaches often discover a number of possible security issues and may or may not accurately identify the true source of the breach in question.  However, what they do point out every time is that it only takes one mistake—one unsecure server, one password that was used on an unsecure system and exposed, one employee who mistakenly clicks on the link in the email, one firewall that wasn’t configured properly, and more—to become the next compromised company in the headlines.

by Kevin Watson, CEO, Netsurion

Kevin WatsonBIO: Kevin Watson joined Netsurion as CEO in November 2014, bringing considerable experience in data security, managed technology services and high-growth technology companies. Netsurion provides cloud-managed firewall solutions to protect the data of small and medium-sized businesses and has been a leader in the field for more than seven years. From 1998-2014, Kevin was co-founder and managing director of C/max Capital where he led the firm’s investments in About.com (taken public then sold to Primedia), Adjoined Consulting (sold to Kanbay), Verid (sold to EMC), Concordia (sold to Kadmon) and KMC Software. Kevin received a Bachelor of Science in engineering from Cornell University.

About Netsurion

Netsurion

Netsurion is a leading provider of cloud-managed IT security  services  that protect small- and medium-sized businesses’  information, payment  systems and on-premise public and private Wi-Fi networks from data  breaches and other risks posed by hackers. Netsurion’s patented remote  installation technology and PCI compliant cloud-based solutions simplify the implementation process and ongoing support. Any sized branch or remote office, franchise or sole proprietor operation can use Netsurion without the costs of onsite support. The company serves the retail, hospitality, healthcare, legal and insurance sectors. www.netsurion.com

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The Real Cost of Inconsistent Third-Party Access

December 18, 20255 Mins Read

What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

August 7, 20256 Mins Read

The Evolving Importance of Identity Governance in FinTech

July 10, 20258 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}