03-15-12 | Blog Post
Who: Blue Cross Blue Shield of Tennessee (BCBST)
Who was affected: Over 1 million members of the BCBST had their information stolen, including names, SSNs, diagnosis codes, birthdates and health plan IDs.
What: 57 unencrypted hard drives were stolen from a leased facility in Tennessee, out of a data storage closet. According to the resolution agreement, the BCBST were relocating staff from the facility and had not yet moved the servers from the closet to their new location.
Charged with: The OCR (Office of Civil Rights, official HIPAA-enforcement entity) found the BCBST failed to have ‘adaquate facility access controls,’ according to their press release. This put them in violation of implementing the appropriate physical safeguards as listed in the HIPAA Security Rule.
They were also found in violation of the administrative safeguards by failing to perform a security evaluation after operational changes.
What they could have done differently: Encrypt all data at rest, including their archived data stored on hard drives. This is a strongly recommended best practice for healthcare organizations that need to meet HIPAA compliance.
They also could have chosen to store their data in a secure, offsite location that had the appropriate physical safeguards/access controls, another important feature of HIPAA compliant data centers.
When: BCBST was alerted October 2, 2009 of an unresponsive server at the facility, but didn’t investigate until October 5, 2009. Official completion date of review, audit and affected individual notification was October 29, 2010.
How much did it cost them: Although the settlement case required BCBST to pay HHS 1.5 million, the company has spent nearly $17 million in investigation, notification and protection costs to date, bringing the total to 18.5 million. Affected individuals received free credit monitoring services, free identity monitoring, consultation, and restoration.
What are their next steps: BCBST encrypted all of its at-rest data, which they claim to be “a voluntary effort which goes above and beyond current industry standards.” While it might not be explicitly required by HIPAA standards, it’s pretty close (read Encrypting Data to Meet HIPAA Compliance for tips) :
A covered entity must, in accordance with §164.306… Implement a mechanism to encrypt and decrypt electronic protected health information.” (45 CFR § 164.312(a)(2)(iv))
BCBST entered a 450 day corrective action plan, which includes sending their written PHI security policies and procedures to HHS, monitoring their employees to ensure they’re trained and following HIPAA compliant policies and procedures, and conduct a risk management plan.
For more on HIPAA violations and the effects of data breaches, try reading How a HIPAA Breach Can Negatively Impact Your Business, or Sutter Health HIPAA Breach: Lessons Learned.
HHS Resolution Agreement
BlueCross, HHS Reach Settlement in 2009 Hard Drive Data Theft
Eastgate Hard Drive Theft
HHS Settles HIPAA Case With BCBST for $1.5 Million