Browsers - Insurance Company Endures an HR Website Nightmare - eWeek Security Watch

Insurance Company Endures an HR Website Nightmare

May 28, 2009
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Aetna, one of the world’s largest health insurance providers, had to do something special for its customers following a security “oops” reported May 26 involving its Website.

It turns out that a number of human resource-related e-mails containing important personal information that had been stored in a “secure” place on the site somehow became public for an undetermined window of time. The e-mails were accessed by a number of visitors to the site, Aetna admitted, although it did not say how many.

As a result, the company will provide free credit monitoring for a year to about 65,000 employees and people who had received job offers during the last five years. No FreeCreditReport.com needed for these folks.

Aetna reported that Social Security numbers of current and former employees and people who received job offers from the company were stored on the Website, which formerly had been maintained by an outside vendor. The site also stored phone numbers, addresses and employment histories for people who had received job offers but elected not to accept them.

Not anymore, though. Aetna has wised up and is now revamping its online HR operation.

An outside firm was called in to do a security review of the site, but it is not been able to figure out how the breach happened in the first place.

Aetna was first tipped off three weeks ago, when it started getting complaints from applicants who received phony e-mails telling them they had been selected for a position. The e-mails — not from Aetna’s HR folks — then requested additional personal information.

Our question is this: What is all that sensitive personal — and personnel — information doing residing on a publicly accessible Website in the first place? Hopefully, Aetna has learned a lesson.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.