Excellus Health Plan suffered a sustained cyber intrusion that began on December 23, 2013 and went undetected until August 2015, with public disclosure on September 9, 2015 and 9,358,891 individuals reported to the HHS Office for Civil Rights as affected (roughly 10.5 million records in total when subsidiary and affiliate plans are counted). Attackers obtained administrative-level access to Excellus systems containing the protected health information of members, patients, and customers of affiliated entities; exposed data included names, dates of birth, Social Security numbers, mailing addresses, telephone numbers, member identification numbers, financial account information, and claims information. On January 15, 2021 Excellus agreed to a $5.1 million HIPAA settlement with OCR to resolve potential violations of the HIPAA Privacy and Security Rules, with OCR citing failures to conduct an enterprise-wide risk analysis, implement adequate technical safeguards, and perform regular information system activity reviews. The accompanying two-year corrective action plan required a comprehensive risk analysis and risk management plan, updated policies and procedures, workforce training, and ongoing OCR oversight; total remediation, litigation, and settlement costs to the insurer have been reported at approximately $17.5 million.
Blog
Insights on AI security and development
Learn how to protect your code, understand AI risks, and build secure workflows with expert insights.

