Class-action lawsuit against health insurer seeks disclosure of network security details following data breach of 80 million members.
Victims of a data breach at health insurer Anthem in February 2015 have filed a class-action lawsuit against the company and are seeking details of an audit by the U.S. Office of Personnel Management (OPM) on Anthem's network security, Modern Healthcare reports. In the cyberattack, hackers compromised personal details of around 80 million Anthem, Blue Cross and Blue Shield members, many of whom have since reported payment card account misuse.
As per the court filing, OPM, which manages the Federal Employees Health Benefit Program, had first carried out a security audit at Anthem in 2013 and pointed out vulnerabilities in its system. It wanted to conduct tests, but this was reportedly turned down by Anthem citing “corporate policy” issues. Shortly after the 2015 cyberattack, OPM conducted a second audit, but its findings were not made public.
The plaintiffs say in their subpoena that if the audit had discovered security flaws, then appropriate action by Anthem would have prevented the subsequent breach and so it was vital the report be disclosed.
Read full story here.
About the Author(s)
You May Also Like
Beyond Spam Filters and Firewalls: Preventing Business Email Compromises in the Modern Enterprise
April 30, 2024Key Findings from the State of AppSec Report 2024
May 7, 2024Is AI Identifying Threats to Your Network?
May 14, 2024Where and Why Threat Intelligence Makes Sense for Your Enterprise Security Strategy
May 15, 2024Safeguarding Political Campaigns: Defending Against Mass Phishing Attacks
May 16, 2024
Black Hat USA - August 3-8 - Learn More
August 3, 2024Cybersecurity's Hottest New Technologies: What You Need To Know
March 21, 2024