Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity

    CareFirst Discloses Breach Affecting up to 1.1M Consumers

    Written by

    Sean Michael Kerner
    Published May 21, 2015
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      CareFirst BlueCross BlueShield publicly revealed on May 20 that it was the victim of a data breach that may have exposed the personal information of up to 1.1 million Americans.

      The CareFirst breach is the third major Blue Cross Blue Shield health care breach disclosed this year, after Anthem (affecting 80 million customers) and Premera (with an impact on up to 11 million people) earlier this year.

      CareFirst began to examine its systems after the Anthem breach disclosure in February and engaged with FireEye’s Mandiant incident response division, which determined that the CareFirst breach occurred in June 2014.

      Mandiant’s analysis shows that attackers gained access to a single CareFirst database. CareFirst noted that the information gained in the breach may have included member names, birth dates, email addresses and subscriber identification numbers. Additionally, CareFirst warned that the attackers may have acquired member-created user names for accessing CareFirst’s Website.

      “CareFirst user names must be used in conjunction with a member-created password to gain access to underlying member data through CareFirst’s Website,” CareFirst stated. “The database in question did not include these passwords because they are fully encrypted and stored in a separate system as a safeguard against such attacks.”

      However, CareFirst emphasized that financial information and medical claims information was not part of the database that attackers breached.

      “Even though the information in question would be of limited use to an attacker, we want to protect our members from any potential use of their information and will be offering free credit monitoring and identity theft protection for those affected for two years,” CareFirst President and CEO Chet Burrell said in a statement.

      CareFirst is also urging affected members to reset the usernames and passwords for their accounts.

      The National Consumers League (NCL) is warning consumers to be wary of phishing attacks in the wake of the CareFirst breach.

      “While the breach does not appear to have compromised sensitive information, such as Social Security numbers, passwords or medical information, cyber-crooks are no doubt busy using the information they did collect to craft convincing-looking phishing emails,” John Breyault, vice president of public policy, telecommunications and fraud at NCL, said in a statement.

      Breyault added that the phishing emails could include the CareFirst logo and look just like the real thing and may contain links or attachments that install malware or direct consumers to Websites designed to steal other information that can be used to commit identity theft or other kinds of fraud.

      Unisys Chief Information Security Officer Dave Frymier warned that a breach of a health care provider like CareFirst can create life-or-death issues for consumers. “If stolen health records are used to obtain care by a criminal, fraudulently purchased medical procedures are listed on the records of people who did not have the procedures,” Frymier stated in an email to eWEEK. “That can create critical medical issues in the future.”

      Frymier is also critical of CareFirst. Organizations seem only to invest in cyber-security after they are attacked, he said, while few seem willing to invest to prevent the attacks in the first place.

      Eric Cowperthwaite, vice president of advanced security and strategy at Core Security, also criticized how the health insurance industry is managing security. Cowperthwaite, who was chief information security officer at Providence Health and Services from 2006 to 2013, said that in the Anthem attack as well as the one against CareFirst, the length of time the attacker was in the companies’ networks before they knew about it was quite long.

      “This is very troubling. If you can’t prevent an attack and you can’t detect an attack, you have a very big problem,” Cowperthwaite stated in email to eWEEK. “The health care industry must wake up and realize that they are subject to the same threats the financial services industry faces.”

      Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

      Sean Michael Kerner
      Sean Michael Kerner
      Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.