Thursday, January 31, 2008

Is Horizon Blue Cross being truthful about the breach?

The following was left as a comment on my original Horizon Blue Cross post. The commenter is apparently a HBCBS employee who's data was compromised:

"bc bs continues. In conversation with employees there yesterday, I saw history being revised as we spoke. by the time the comments from bc were in the paper today they were totally different than what I had been told as one of the 300,000 now exposed.

The employee was a male. Supposedly several days after the theft BC "destroyed" the files that had been on the computer and did this for the next 'several days". On January 23 the hard drive "self destructed".

I was told that it was "policy" that laptops with this kind of info left their premises and now that is being reconsidered.

yesterday it was made very clear that they are not sure if medical data was on the computer or not. Today, in their press remarks it is being presented as if no medical data was on the computer.

So... what was the role of the person walking around with all our info exposed? I was also told that no one had asked the person if medical data was on the computer.
it's a nice distraction to have Experian provide tracking.

What about BC providing internal tracking to the 300,00 for the possible exposure of policy info and access.

What a perfect storm for a shady practitioner to bill thru the stolen policy using universal claims forms and for BC to pay on the "claim" to that person who generously then shares with the thief.

Meanwhile...the legit policy holder has brand new medical codes slammed on them, blue cross math already questionable becomes even more screwed up and no one at Experian will be protecting or guarding or informing about that.
Blue is offering scant protection and a major distraction from what is really the most serious exposure here. why is that not surprising?"

No comments: