DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Former Aetna employee arrested; found in possession of members’ identity information

Posted on March 28, 2015 by Dissent

Aetna Insurance has also reported a breach in recent months, but unlike the Anthem and Premera Blue Cross breaches, the Aetna breach does not appear to have been a massive one.

In a letter dated January 8, the insurance company notified the Maryland Attorney General’s Office that six Maryland residents were among those being notified that their information had been found in the possession of a former employee who had been arrested in Florida. The data theft was reported to Aetna by the IRS.

As Aetna explains:

On December 2, 2014, Aetna’s Investigative Services unit received notification from the IRS that a former Aetna employee had been arrested in Florida. The arrest took place in April 2014. The individual stopped working for Aetna in August 2013. The former employee’s personal cell phone was confiscated and pictures of screen shots from Aetna computer screens were found on it. The IRS has the cell phone and is conducting a criminal investigation of possible identity theft. The IRS also provided copies of the cell phone pictures to Aetna.

So it appears the data theft had occurred before August 2013 but was never detected (somewhat understandably if these were screen shots taken from a computer). Why law enforcement delayed over 7 months before notifying Aetna was not explained.

Aetna’s Investigative Services unit reviewed the pictures and found that 133 Aetna disability members had their name, date of birth, social security number and employer name captured in the screen shots.

Some of the pictures were blurry and only certain fields could be read by our investigators. However, in late December, by cross referencing information in our systems, we were able to recreate the data on the pictures. While it is unlikely that all members’ information was legible enough to be at risk, all of them are being notified of the incident and offered free credit monitoring services.

Aetna made a point of noting that they had conducted a criminal background investigation before hiring the employee in 2007. “A subsequent background check revealed no criminal activity for this employee from 2007 to August 2013, when she left our employ,” Aetna’s Chief Privacy Officer reports.

This is not the first time we’ve seen insiders take screenshots of computer screens for an ID theft scheme (cf, this case or  this case). I’d be curious to see what hospitals are doing to prevent this type of data theft.

Related: Notification letter template and notification template, Page 2

Category: Health DataID TheftInsiderU.S.

Post navigation

← Stolen Uber Customer Accounts Are for Sale on the Dark Web for $1
Nite Ize notifies consumers after hack at services provider →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Episource notifying 5.4 million patients of cyberattack in January
  • Investigation of 2024 Helsinki data breach – Report
  • Major trial underway for data leak that left 72,000 victims in France
  • Anubis: A Closer Look at an Emerging Ransomware with Built-in Wiper
  • HealthEC Agrees to $5.48 Million Settlement to End Data Breach Lawsuit
  • US offering $10 million for info on Iranian hackers behind IOControl malware
  • Sompo Japan Insurance submits improvement plan after info leakage
  • Moreno Valley, Calif., Schools Report Data Breach
  • The Growing Cyber Risks from AI — and How Organizations Can Fight Back
  • UPDATING: Credit Control Corporation denies any current breach

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • DOJ Seeks More Time on Tower Dumps
  • Your household smart products must respect your privacy – including your air fryer
  • Vermont signs Kids Code into law, faces legal challenges
  • Data Categories and Surveillance Pricing: Ferguson’s Nuanced Approach to Privacy Innovation
  • Anne Wojcicki Wins Bidding for 23andMe
  • Would you — or wouldn’t you?
  • New York passes a bill to prevent AI-fueled disasters

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.