Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

sadoldgirl

(3,431 posts)
Fri Feb 13, 2015, 06:34 PM Feb 2015

A question for other members

of Anthem (Blue Cross/shield).

After they hacked the insurance's computer files, are we
supposed to let SS know, that our numbers may be
abused? Is Anthem supposed to tell us whose information
is now endangered?
Does anyone here know?
Thanks

10 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
 

Electric Monk

(13,869 posts)
2. Why truncate your subject line? I suggest a quick edit to get better replies.
Fri Feb 13, 2015, 06:39 PM
Feb 2015

You currently have:

A question for other members
of Anthem (Blue Cross/shield).

After they hacked the insurance's computer files, are we
supposed to let SS know, that our numbers may be
abused? Is Anthem supposed to tell us whose information
is now endangered?
Does anyone here know?
Thanks


I think this would be better:

A question for other members of Anthem (Blue Cross/shield).

After they hacked the insurance's computer files, are we
supposed to let SS know, that our numbers may be
abused? Is Anthem supposed to tell us whose information
is now endangered?
Does anyone here know?
Thanks


It's a much clearer subject line this way, and that's what the subject line is for
 

bigwillq

(72,790 posts)
3. I clicked on it because it was a "cliffhanger" subject
Fri Feb 13, 2015, 06:42 PM
Feb 2015

I probably would not have clicked on it if the subject included "Anthem (Blue Cross/Shield)".

trackfan

(3,650 posts)
5. I have mine through work. They're offering free enrollment in an ID theft protection plan.
Fri Feb 13, 2015, 06:45 PM
Feb 2015

I'm not sure if this is a company benefit for our group, or if Anthem is offering this to all subscribers. You should check.

 

Maedhros

(10,007 posts)
6. Portions of the Graham-Leach-Bliley Act (GLBA) require reporting by institutions
Fri Feb 13, 2015, 06:45 PM
Feb 2015

that are victims of a data breach, as do portions of other Federal and State laws.

This is a decent summary:

http://www.datasecuritylawjournal.com/2012/05/06/federal-data-breach-notification-laws/

Examples of federal laws that require data breach notification are two laws governing the health care industry – the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health Act (HITECH). Together, these laws require “covered entities” and many of their service providers to maintain administrative, technical, and physical safeguards to ensure the confidentiality, integrity, and availability of “protected health information” (commonly referred to as “PHI”). A covered entity is a health plan, a health clearinghouse, or a health care provider who transmits health information.

If there is a breach, the covered entity must notify the individuals whose information has been accessed (and law enforcement) without unreasonable delay and no later than 60 days after the breach was discovered. (The law also requires notification to the media in cases where the breach affects more than 500 individuals). Whether there is a breach that triggers the duty to notify depends on whether, with some exceptions, there was an impermissible use or disclosure that compromises the security or privacy of the PHI such that the use or disclosure poses a significant risk of financial, reputational, or other harm to the affected individual. The notice must state what occurred, what type of information was accessed by the breach, what steps individuals should take in response, what is being done to investigate, mitigate, and protect against further harm, and contact information should be provided. HITECH imposes these same notification requirements on the covered entity’s vendors and service providers.


I do not know if these laws require notifying the Social Security Administration...

sadoldgirl

(3,431 posts)
9. Thank you all for your help,
Fri Feb 13, 2015, 07:05 PM
Feb 2015

sorry if I offended anyone with the title of the OP.
Several million people might be affected by this; thus
I don't think that I asked a useless question.

I will try the anthem site, and then call SS just
in case of necessity.

Have a great weekend.

 

DisgustipatedinCA

(12,530 posts)
10. I wouldn't worry about people wasting time writing posts about wasting time.
Fri Feb 13, 2015, 07:37 PM
Feb 2015

That's kind of one of those self-contained asked-and-answered things. It was a good question. Enjoy your weekend.

Latest Discussions»General Discussion»A question for other memb...