Concenta Preferred Systems of Waymouth, Mass., audits medical claims for hospital stays of Nationwide customers and stored its backup tapes containing the customer information in a lockbox. The tapes included hospital stay information, medical data, and Social Security numbers for the customers.
If such a reader were used, the data is still "in a functionally encoded and restricted state. It would look like gobbledygook" to anyone who was not a skilled auditor of the data, he says.
There has been no reported misuse of customer data since the burglary, but Nationwide is only now informing customers that their data was stolen. Switzer says Nationwide is offering customers free identify theft insurance and credit monitoring for a year.
Nationwide would be smart to encrypt data tapes handed over to subcontractors in the future, says Gordon Rapkin, CEO of Protegrity, a firm that provides data security services. "You can outsource the process of auditing the data, but you can't outsource your responsibility for it," he says.
Nationwide customers for auto, life and homeowners insurance were not affected by the theft. Switzer said most of the affected customers are residents of Ohio. Nationwide Health Plans sells health insurance in that state and a part of California.
In another recent data theft, retail chain owner TJ Maxx experienced a hack of its computer systems in December in which customer credit card information was stolen. TJ Maxx owns 751 Marshalls, 826 TJ Maxx, and 251 Homegoods stores in the United States
The Cyber Security Industry Association is pushing for a bill to require stricter management of personal identity information by businesses.
Stay connected and informed by visiting the CA Solutions Center Community!

Become a member today for instant access to free InformationWeek research, expert advice, peer perspectives, and more on the following topics:
- Application Performance Management (APM)
- Security Management
- Mainframe 2.0
- IT Automation
- Service Assurance
Also, visit our Government and Financial Services groups to see how these technologies apply specifically to those industries.
NOTE: Offer valid for U.S., U.S. possessions, & Canada only.