Diberdayakan oleh Blogger.

Jumat, 06 Februari 2015

Anthem Hacking - Perspective

by Handoyo susanto  |  at  12.00
In comments to one of our previous posts on this topic, Co-Blogger Bob makes a terrific point:

"Not taking anything away from Mandiant as they are the "A team" when it comes to tracking down hackers ... Most companies do very little when it comes to cybersecurity and many (mo st?) have probably been hacked and just don't know it."

This morning, the Wall Street Journal reported that "Anthem Inc. stored the Social Security numbers of 80 million customers without encrypting them." On the face of it, this seems pretty unconscionable.

But is it?

I reached out to several of our carriers, and to AHIP (America’s Health Insurance Plans), which represents (most of) the carriers. I had but one question:

"Is this an egregiously unusual oversight, or industry standard?"

That is, is Anthem an outlier here, or do most carriers leave that kind of information unencrypted? The folks at AHIP were kind enough to send me a copy of the HHS regs on the subject, but also told me that they'd not surveyed their members on it, so can't tell me whether or not this is SOP.

I'm still waiting to hear back from my carriers, and will update this post as appropriate.

JUST IN from Anthem:

Members who may have been impacted by the cyber attack against us should be aware of scam email campaigns targeting current and former members.  These scams, designed to capture personal information (known as “phishing”) are designed to appear as if they are from a health plan and the emails include a “click here” link for credit monitoring. These emails are NOT from us.

• DO NOT click on any links in email.
• DO NOT reply to the email or reach out to the senders in any way.
• DO NOT supply any information on the website that may open, if you clicked on a link in email.
• DO NOT open any attachments that arrive with email.

We are not calling members regarding the cyber attack and are not asking for credit card information or social security numbers over the phone.

Friday LinkFest

by Handoyo susanto  |  at  10.49
So, several items that, while blogworthy, don't seem to merit their own dedicated post:

■ As we've already seen, the future of health care CO-OPs is, at best, rocky. At the Employee Benefit Advisor, Bruce Shutan looks under the hood, and notes that "it captured nearly a quarter of the total enrollment for all 23 consumer-operated and oriented plans known as CO-OPs operating in 24 states," all on a "shoe-string" budget.
Bruce has some thoughts on how this will play out as we go forward..

■ FoIB Holly R tips us to this tidbit of tantalizing info:

"The White House cyber czar may have had personal information leaked in the recent Anthem data breach."

That breach, news of which is still evolving, may end up "touching" a lot more folks than originally believed.

■ As we've noted many times, wine (especially the reds) have been linked to several positive health effects. Turns out, that IPA you were drinking last Sunday may also help:

"[B]eer also confers some health benefits, according to a new study, which found a compound within can ward off dementia and other cognitive decline."

L'chaim!

Obamacare Enrollment Update

by Handoyo susanto  |  at  02.00
The folks that brought us Obamacare and a non-working website like to keep those who are interested up to
date on the latest score. The latest installment for week 10 of the Obamacare open enrollment saga goes like this.
Since Open Enrollment began on November 15, almost 7.3 million consumers selected a plan or were automatically re-enrolled through the HealthCare.gov platform, which includes the Federally Facilitated Marketplace (FFM), State Partnership Marketplaces and supported State-Based Marketplaces. - HHS
7.3 million selected a plan or were re-enrolled.

Sounds a lot like the stimulus reports about jobs created or saved.

Selecting a plan does not mean actually applying for coverage. Nor does it mean the premium was paid. In DC-speak it means window shopping.

The same is true for the automatic re-enrollment.

Until you actually PAY for your policy you don't have coverage.

Isn't it odd how they fail to count the number of people that actually LOST health insurance because of Obamacare?

Kamis, 05 Februari 2015

Anthem Hacked [UPDATED]

by Handoyo susanto  |  at  06.48
Picking up on where Bob left off ...

As you've no doubt already heard, hackers were able to gain access to Anthem's systems, and access the personal information of both clients and employees (it's not clear whether "employees" include independent agents/brokers who represent the carrier). All told, it appears that over 80 million folks were affected.

To its credit, Anthem sent out an email last night addressing the problem:

To our valued business partner:

Safeguarding your clients’ personal, financial and medical information is one of our top priorities, and because of that, we have state-of-the-art information security systems to protect your data. However, despite our efforts, Anthem was the target of a very sophisticated external, cyber attack. These attackers gained unauthorized access to Anthem’s information technology (IT) system and have obtained personal information from our current and former members such as their names, birthdays, member ID/Social Security numbers, street addresses, email addresses and employment information, including income data. Based on the information we know now, there is no evidence that banking, credit card, medical information (such as claims, test results, or diagnostic codes) were targeted or compromised.

Once the attack was discovered, Anthem immediately made every effort to close the security vulnerability, contacted the Federal Bureau of Investigation (FBI) and began fully cooperating with their investigation. Anthem has also retained Mandiant, one of the world’s leading cybersecurity firms, to evaluate our systems and identify solutions based on the evolving landscape. [ed: emphasis added, see below]

Anthem’s own associates’ personal information was accessed during this security breach. We join you in your concern and frustration, and we assure you that we are working around the clock to do everything we can to further secure your clients' data.

Anthem will individually notify current and former members whose information has been accessed. We will provide credit monitoring and identity protection services free of charge so that those who have been affected can have peace of mind. We have created a dedicated website (www.AnthemFacts.com) where members can access information such as frequently asked questions and answers. We have also established a dedicated toll-free number that both current and former members can call if they have questions related to this incident. That number is: 1-877-263-7995. As we learn more, we will continually update this website and share that information with you.

We want to personally apologize to you and your clients for what has happened, as we know you expect us to protect your information. We will do everything in our power to make our systems and security processes better and more secure, and hope that we can earn back your trust.

Sincerely,

Ken Goulet
President, Commercial and Specialty Business

Erin Hoeflinger
Ohio Plan President

 

Regarding Mandiant and cyber-remediation: on the one hand, this seems very much like closing the barn door. On the other, at least they recognize their vulnerability, and are seeking to mitigate and minimize it. One suspects that Mandiant (and its competitors) will be very busy going forward, as other insurers take stock of their own potential weak spots.

UPDATE: FoIB Holly R catches this from Bloomberg:

"... hackers obtained data on tens of millions of current and former customers and employees"

And asks: "How former?"

Good question, disturbing implications.

Blue Attack

by Handoyo susanto  |  at  04.40
Anthem Blue Cross policyholder data hacked. Possible 37 million affected.
The information accessed during the "very sophisticated attack" did include names, birthdays, social security numbers, street addresses, email addresses and employment information, including income data, the company said. - Yahoo News


Rabu, 04 Februari 2015

Taxes, Shmaxes

by Handoyo susanto  |  at  08.48
Thanks to Moe Lane, we have this little gem:

"Consumers who received too much in federal tax credits ... got a reprieve of sorts from the Internal Revenue Service this week. Although they still have to repay ... excess subsidies, the IRS won’t ding them with a late payment penalty if they don’t repay it by the April 15 tax deadline."

Which is nice for them, but creates a problem:

"The Equal Protection Clause of the 14th amendment of the U.S. Constitution prohibits states from denying any person within its jurisdiction the equal protection of the laws."

So what's the problem?

Well, suppose you owe taxes on something (other than the subsidy clawback), and fail to pay on time: you're still subject to fines and interest. But for the special snowflakes that "miscalculated" their subsidies, well, no worries, mate.

Of course, it's not really a problem at all, at least according to the Obamastration:

"White House Press Secretary Josh Earnest described reports that millions of Americans would be getting tax bill because of Obamacare as "inaccurate" just days after the Treasury Department estimated that 6 million Americans will pay about $2 billion in individual mandate taxes this year."

Left hand meet right hand.

Sheesh.

Senin, 02 Februari 2015

Guest Post: The Force(d) is with You

by Handoyo susanto  |  at  11.05
From time to time, we host guest posts from esteemed colleagues and other bloggers. These are typically for insurance-related matters that fall outside our own particular wheelhouse. Today, we're pleased to bring you this post from Dennis Wall,  an elected member of the American Law Institute, author of several legal and risk-related books, and proprietor of the Insurance Claims And Issues blog.

If you've ever bought a house, you know that the lender requires you to insure it. Sometimes, folks let their coverage lapse, and the lender then obtains its own coverage, "forcing" it onto the property (and the homeowner). Today, Dennis explains the implications in this economy:

The “Great Recession” of 2008-2009 has caused a lot of harm. No harm has been felt more keenly than by people involved with residential mortgages and home loans.

During the six years leading up to the Great Recession, or from 2002-2007, mortgage debt rose nearly as much as it had since the United States was founded. Household mortgage debt rose an average of $60,000.00 during those same six years, or about $10,000.00 each year for each home in the United States. That is also the time when the once-standard 30-year fixed rate mortgage with a 20% down payment was no longer the mortgage loan of choice. [Findings from report of the Financial Crisis Inquiry Commission. THE FINANCIAL CRISIS INQUIRY COMMISSION FINAL REPORT, January, 2011].

A forensic investigation over three years, including research into publicly available federal court electronic filings, reveals clearly that many business practices have deliberately been kept secret concerning the sale, maintenance and monitoring of mortgages. In particular, the practices of a small number of insurance companies offering force-placed insurance to lenders has dramatically driven up the price of lender force-placed insurance or LFPI.

LFPI is insurance which protects the lender’s interest in the borrower’s collateral. It is “collateral protection insurance” in the sense that it is insurance which protects only the collateral.

Kickbacks and other alleged premium add-ons drive up the price of lender force-placed insurance. Some call the process “reverse competition” or “pay to play.” LFPI premiums are paid by the borrowers and not by the lenders. That is, the premiums for LFPI are paid by homeowners and not by the banks. A three-year review of federal court files reveals that the only complaints which survive in court are the complaints in which the homeowners complain about the extra charges added on to the monthly premiums they pay.

The notion that lenders force-place insurance only when borrowers do not meet their obligations, is largely a myth. It is far more likely that lenders will force-place insurance and let the homeowners oppose it if the homeowners can. To the contrary, homeowners make their monthly mortgage payments for the most part – until they no longer can make the payments including the added burden of premiums for “pay to play” force-placed insurance. Then the lenders and their agents foreclose, and the mortgage machine starts all over again.


Thanks, Dennis! And look for his new book, “Lender Force-Placed Insurance,” due out this Spring.

Proudly Powered by Blogger.