Tampilkan postingan dengan label Health Net. Tampilkan semua postingan
Tampilkan postingan dengan label Health Net. Tampilkan semua postingan

Kamis, 17 Maret 2011

Medical Data Breach of the Month Department: Health Net Once Again a Star in the Healthcare Renewal Theatre

I have written frequently about the breaches of electronic information security, such as at my posts:

"Networked EMR's and Healthcare Information Security: Practical When Massive IT Security Breaches Continue?"

"Networked, Interoperable, Secure National Medical Records a Castle in the Sky?"

"Operation Aurora And a Widespread Reluctance to Discuss IT Flaws: Is Universal Healthcare IT Really a Good Idea in 2010?"

Medical data breach of the week - but your EMR data is secure, trust us, we're IT experts

and others.

This latest medical information breach only affected a mere 2 million people this time.

Perhaps we should go for 20 million next time?

And then - there were substantial delays in notification (to give identity thieves time to get rich?)

Health Net Delays Notification of Data Breach Involving 2 Million People

By: Brian T. Horowitz
2011-03-16

Insurer Health Net waited until March 14 to disclose a data breach discovered on Jan. 21 involving the loss of nine server drives and the data of 2 million customers, employees and health care providers.

Health Net, a provider of health insurance to about 6 million people across the United States, has come under fire for reporting the loss of nine server drives at its data center in Rancho Cordova, Calif., nearly two months after it occurred.

More than 2 million Health Net members, employees and health care providers may have been affected by the data breach, including about 845,000 California policyholders, according to The San Francisco Chronicle. California regulators are investigating the breach, the newspaper reports.

How did this happen?

The insurer found out about the security lapse on Jan. 21, when IBM, which manages the company's IT infrastructure, informed Health Net that it was unable to locate server drives, according to a recording on Health Net's data breach hotline (855-434-8081).

These drives perhaps are of a new technology, with motorized robotic legs that allow them to walk away.

Or perhaps the drives were like this, where the round drive platter stacks perform double duty as wheels:


A "mobile" hard drive. Click to enlarge.


The drives just rolled away - to the tune of Steppenwolf's "Born to be Wild" ...


These drives were just Born to be Wild! Click to play.


Get your motor runnin' ... head out on the highway ...

The health benefits provider began its investigation at that time and learned that the nine drives included personal information for former and current Health Net members, employees and health care providers. The company didn't report the breach to the public until March 14.

Gee, thanks.

Health Net spokesman Brad Kieffer declined eWEEK's request for additional information on the breach but said, "We continue investigating unaccounted for server drives, and out of an abundance of caution we are notifying our members."

"Abundance of caution" and an almost 2-month delay do not belong in the same news story.

... "Given the size and type of data lost, this is a serious breach, and those affected should have been notified and protected immediately when IBM notified Health Net of the loss," Rob Enderle, principal analyst for the Enderle Group, wrote in an e-mail to eWEEK.

Indeed.

"While the delay was likely due to the belief that these drives were either misplaced or reused and not logged and the hope they would turn up on a maintenance rotation, the exposure to those that may have been compromised is excessive, and for an insurance company not to immediately mitigate this exposure�unforgivable," Enderle said.

"Hope/keeping your fingers crossed" and "due diligence/corporate responsibility" also do not belong in the same paragraph.

Information included names, addresses, health information, Social Security numbers and/or financial information, Health Net reports. .

All the news that's fit to print.


The Health Net breach could be the most serious health care data breach since 2008, when incidents affected 2.2 million people at the University of Utah and 2.1 million people at the University of Miami, according to the San Francisco Chronicle report.

Since 2008, eh, way back when, ancient history, when dinosaurs ruled the earth?

In May 2009, Health Net suffered another security breach in which a portable disk drive holding the medical and financial data on 1.5 million members disappeared from its Connecticut headquarters.

The portable disk drives must have robotic legs, too.

Data breach penalties for Health Net could be severe, according to Enderle.

Perhaps that's why they were crossing their fingers hoping the drives would turn up somehow?

Finally, I note that this company has also been busy in recent years making a name for themselves in the Healthcare Renewal Theatre in other ways. They're stars! See http://hcrenewal.blogspot.com/search/label/Health%20Net

-- SS

Jumat, 03 Desember 2010

Health Insurers Sanctioned, Fined

It has not been a good few weeks for big US health insurance companies.  First was a report (e.g., per the Wall Street Journal) that three companies had been suspended from selling Medicare Advantage plans:
The U.S. government's Medicare program has ordered three health insurers--Universal American Corp. (UAM), Health Net Inc. (HNT) and Arcadian Health--to stop marketing to and enrolling new members in their Medicare Advantage health and prescription-drug plans, saying the companies violated regulations.

In particular,
Universal American was told to stop marketing to and enrolling people in its Medicare Advantage plans effective Dec. 5. The action doesn't affect current members or the enrolling of beneficiaries in the company's stand-alone Medicare prescription-drug plans.

Health Net had to suspend the marketing of and enrollment in its Medicare Advantage plans and stand-alone Medicare prescription-drug plans as of Friday, as the government said the company's conduct poses a 'serious threat' to enrollees. The sanction doesn't affect the status of current enrollees, however.

In a letter Friday to Theodore Carpenter, head of Universal American's Medicare Advantage business, the Centers for Medicare and Medicaid Services alleged the company has a 'longstanding pattern of prohibited marketing practices targeted to highly vulnerable populations in violation' of federal law and guidelines as well as contractual terms with CMS.

Universal American is a 'chronic poor performer' with respect to the regulations, according to CMS, which said the company's agents engaged in aggressive sales tactics and abusive behavior, and misled or confused beneficiaries or misrepresented the plan.

The agency's letter to Health Net government-programs executive Scott Kelly said the company's conduct 'poses a serious threat to the health and safety of its enrollees,' as a result of the company's 'intractable failure to provide its enrollees with prescription drug benefits in conformance" with laws, guidelines and contract terms.' CMS cited a 'history of non-compliance.'

Then, the state of California fined and ordered restitution from multiple companies, as reported by the San Francisco Chronicle:
State regulators Monday fined seven of California's largest health insurers nearly $5 million for systematically failing to pay doctors and hospitals fairly and on time.

The California Department of Managed Health Care issued the fines following an 18-month audit in which investigators looked at a small but statistically significant sample of claims. The investigation found the plans were paying on average about 80 percent of the claims correctly, far below the legal threshold of 95 percent.

'Our clear and consistent message is that California's hospitals and physicians must be paid fairly and on time,' said Cindy Ehnes, director of the Department of Managed Health Care, which is charged with regulating the states' health maintenance organizations, or HMOs.

In addition to the fines, the companies must pay the doctors and hospitals restitution that is expected to run into the "tens of millions of dollars," Ehnes said. The plans will also be required to come up with a plan to correct the problem and submit to future audits.

Failing to pay providers properly makes it tougher for them to survive in the struggling economy, Ehnes said. 'If providers are not paid, patient care and access suffer,' she said.

Regulators fined Anthem Blue Cross and Blue Shield of California $900,000 each. United/PacifiCare was fined $800,000 and Kaiser Foundation Health Plan and Health Net were both hit with fines of $750,000.


The fines for Cigna and Aetna were $450,000 and $300,000, respectively, for a total of $4.85 million.

Please note that some of these companies have become "frequent flyers" on the Health Care Renewal blog.  Anthem Blue Cross in California is a subsidiary of WellPoint. WellPoint, in particular, just appears again and again on Health Care renewal.  A list of all posts about that company is here, and see this post for a list of past ethical and management missteps.  Health Net appeared in both stories above, and appeared on Health Care Renewal here.  Posts on Aetna are here.

Having been writing for this blog now for several years, I am struck by how often the conduct of particular health care organizations has been discredited, without any discernible effect on the organization's leadership or course.  It is particularly striking how the attention paid and pay given to the leaders of some health care organizations contrasts with the public record of their organization's bad behavior.

In particular, contrast the long catalog of misbehavior by WellPoint, noted above, with the enormous earnings of the company's CEO (more than $13 million in 2009), and her status as a prominent speaker on health care policy (see post here). 

In the laissez faire, anything goes, wild, wild west economy of today, spearheaded by the financial service companies that lead us to the global economic collapse, it seems that ethical leadership counts for nothing.  This is bad when it applies to the leadership of financial services, whose bad leadership can cost us all a lot of money.  It is worse when it applies to health care, whose bad leadership can cost us our health and our lives.

As I have said ad infinitum, to really reform health care, we will need to get accountable, ethical, transparent leadership of health care organizations.