DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

HealthPartners: Insurance client data was breached 2008-10

Posted on March 21, 2014 by Dissent

Christopher Snowbeck reports:

Bloomington-based HealthPartners is sending letters to about 38,000 health plan members regarding a privacy breach that occurred between 2008 and 2010.

The breach involved a HealthPartners employee who wrongly shared information with a family member in order to get help formatting files to prepare quality improvement reports, according to a news release issued Friday by the health insurer.

Files also were improperly copied to multiple devices in order for the employee to work from home. As a result, the insurance company says it has recovered several devices, and continues to look for others, that could contain the data.

Read more on Pioneer Press.

A statement, linked from HealthPartner’s home page, says:

As an administrator of health plans, HealthPartners collects and maintains personal information about our members. We recently learned about an incident that involved some of our health plan members’ personal information.

In addition to notifying affected members by letter, we also are posting this information to our Web site. The following information explains what happened, what it means for those affected, and how you can find answers to any questions you may have.

What happened?

We received a call on January 21, 2014. The call was about a HealthPartners employee who had taken home electronic files with health plan information.

We began an investigation. We learned that this happened between 2008 and 2010. The employee showed the data to a family member to get help with the files. The files were copied to several computers and devices so the employee could work from home.

We believe the employee and the family member meant no harm, but this was wrong. It was against our rules for handling member information. We have recovered several computers and devices involved. We continue attempts to locate any possible others.

We are sorry that this has happened and apologize to those who have been affected.

Was my information in the files and how can I know?

On March 4, 2014, we were able to identify the members whose information was in the files.  We have mailed letters to those members to let them know about this mistake.

If you did not receive a letter and still wish to verify whether you were affected or not, please call us at 1-866-316-1495.

What kind of information was involved?

Information that was not in the files:

  • Medical records
  • Credit card information
  • Social security numbers (with one exception, see below)
  • Member addresses
  • Member telephone numbers
  • Email addresses

The files did include member name, date of birth, and health plan member number.

In some cases, the files included gender, provider name and location, and a general description of health care services received, and feedback members gave to us about services they received.

One member’s social security number was in the files.  We have already contacted that member directly by telephone.

What is HealthPartners doing for those who were affected?

In the notification letters we have sent to affected members, we are offering them one year of free identity protection provided by First Watch Technologies, Inc.  We are asking affected members to call 1-866-316-1495 if they would like to use this service.

We do not believe there is risk for identity or financial theft. The shared information was limited. We do not believe the information was shared with anyone other than the employee’s family member. We also do not believe the information was used for anything other than the employee’s work.

What is HealthPartners doing to make sure this won’t happen again?

We regret this mistake. We promise to use what we have learned to make improvements. We are always working to do more to protect member information. For example, we encrypt all laptops, smart phones, flash drives, and other devices used for company business. This makes data unreadable if it gets into the wrong hands. We will also have more employee training about how to keep member information safe.

Who should I call if I have questions?

We apologize. We want to earn and keep your trust. We know that our members may have questions, so we have set up a special call center. Please call 1-866-316-1495 if you have questions or would like to talk with us more.

Category: Uncategorized

Post navigation

← UK: ICO decides against probe of Santander email spam scammers
Rosenthal Wine Shop discloses malware may have compromised customers’ payment card info →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • FTC Finalizes Order with GoDaddy over Data Security Failures
  • Hacker steals $223 million in Cetus Protocol cryptocurrency heist
  • Operation ENDGAME strikes again: the ransomware kill chain broken at its source
  • Mysterious Database of 184 Million Records Exposes Vast Array of Login Credentials
  • Mysterious hacking group Careto was run by the Spanish government, sources say
  • 16 Defendants Federally Charged in Connection with DanaBot Malware Scheme That Infected Computers Worldwide
  • Russian national and leader of Qakbot malware conspiracy indicted in long-running global ransomware scheme
  • Texas Doctor Who Falsely Diagnosed Patients as Part of Insurance Fraud Scheme Sentenced to 10 Years’ Imprisonment
  • VanHelsing ransomware builder leaked on hacking forum
  • Hack of Opexus Was at Root of Massive Federal Data Breach

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Meta may continue to train AI with user data, German court says
  • Widow of slain Saudi journalist can’t pursue surveillance claims against Israeli spyware firm
  • Researchers Scrape 2 Billion Discord Messages and Publish Them Online
  • GDPR is cracking: Brussels rewrites its prized privacy law
  • Telegram Gave Authorities Data on More than 20,000 Users
  • Police secretly monitored New Orleans with facial recognition cameras
  • Cocospy stalkerware apps go offline after data breach

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.