DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Call center employee attempts to extort German health insurer

Posted on February 14, 2010 by Dissent

Die Krankheitskarte web site reports:

German health insurance company (or rather: sickness fund) “BKK Gesundheit” was eager to outsource its telephone hotline to a virtual call center. In their home offices, the untrained workers then could retrieve data they weren’t allowed to see, including medical diagnoses. They all had access to „an unneccessary huge amount of data“.

How was this uncovered? A former member of staff wanted to press money from the fund…

Dr. Ewald Proll, who posted the entry [original in German, here], was kind enough to translate and elaborate on the story for PHIprivacy.net:

The insurer, BKK Gesundheit, is the largest of a subgroup of German health insurance funds with about 1.5 million members. BKK Gesundheit had contracted with MediaKom Verlag GmbH & Co. KG, which, in turn, contracted with Value 5 HealthCare GmbH to provide a 24-hour call service for their insured members.

The “call centers,” however were actually home offices from which the untrained staff could remotely log in to the insurer’s database and where — seemingly due to inadequate security — they could access more information than necessary for their job. Although the staff reportedly could not copy, print, or download the information in the database, it may have been possible for them to take and store screenshots of members’ records that included diagnostic information.

According to published sources, an employee of Value 5 HealthCare GmbH attempted to extort the insurance fund, threatening to the publish the sensitive health information if the company didn’t pay. The insurer did not pay the extortion and referred the matter to legal authorities while securing the database from further access.

The story was uncovered by a TV team.

It will be interesting to see what, if any, fines or actions Germany takes over this breach. Certainly any attempt to extort a health insurer with threats of releasing confidential or what should be protected health information is a criminal matter, but what about the insurer’s actions in contracting and subcontracting with staff where there may not have been adequate security protections? Under Germany’s data protection laws, they might be subject to some consequences.

This entry was crossposted from phiprivacy.net

Related posts:

  • Call center employee attempts to extort German health insurer
  • Operation Anti Security Breakdown and targets, the full time line
Category: Breach IncidentsHealth DataInsiderNon-U.S.Of NoteSubcontractor

Post navigation

← Call center employee attempts to extort German health insurer
MT: Gateway woman pleads guilty to fraud, ID theft →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Ex-student charged with wave of cyber attacks on Sydney uni
  • Detaining Hackers Before the Crime? Tamil Nadu’s Supreme Court Approves Preventive Custody for Cyber Offenders
  • Potential Cyberattack Scrambles Columbia University Computer Systems
  • 222,000 customer records allegedly from Manhattan Parking Group leaked
  • Breaches have consequences (sometimes) (1)
  • Kansas City Man Pleads Guilty for Hacking a Non-Profit
  • British national “IntelBroker” charged with causing $25 million in damages; U.S. seeks his extradition from France
  • France issues press statement about arrest of ShinyHunters members
  • Patients Allege Home Delivery Pharmacy Failed to Timely Notify Them of Data Breach
  • Hackers breach Norwegian dam, open valve at full capacity

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Microsoft’s Departing Privacy Chief Calls for Regulator Outreach
  • Nestle USA Settles Suit Over Job-Application Medical Questions
  • NY Attorney General James Affirms Hospitals Must Provide Access to Emergency Abortion Care
  • How Internet of Things devices affect your privacy – even when they’re not yours
  • Sky Views Personal Data as a Potential Weapon in IPTV Piracy War
  • Florida Used a Nationwide Surveillance Camera Network 250 Times To Aid in Immigration Arrests
  • Federal Court Strikes Down HIPAA Reproductive Health Care Privacy Rule

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.
Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report