The thieves made off with backup tapes but would need a special data reader with matching software.
Nationwide Mutual Insurance is notifying 28,279 customers of its health insurance unit, Nationwide Health Plans, that their data was stolen during an Oct. 26 burglary of the offices of a subcontractor.
Concenta Preferred Systems of Waymouth, Mass., audits medical claims for hospital stays of Nationwide customers and stored its backup tapes containing the customer information in a lockbox. The tapes included hospital stay information, medical data, and Social Security numbers for the customers.
The box was taken during an Oct. 26 theft, along with computers, DVD players, and other electronic gear that appeared to have immediate street value, says Nationwide spokesman Mike Switzer. To find the information on the tapes requires "a very specific high-tech tape reader with matching software," that police concluded was unlikely to be accessible to the thieves, says Switzer.
If such a reader were used, the data is still "in a functionally encoded and restricted state. It would look like gobbledygook" to anyone who was not a skilled auditor of the data, he says.
There has been no reported misuse of customer data since the burglary, but Nationwide is only now informing customers that their data was stolen. Switzer says Nationwide is offering customers free identify theft insurance and credit monitoring for a year.
Nationwide would be smart to encrypt data tapes handed over to subcontractors in the future, says Gordon Rapkin, CEO of Protegrity, a firm that provides data security services. "You can outsource the process of auditing the data, but you can't outsource your responsibility for it," he says.
Nationwide customers for auto, life and homeowners insurance were not affected by the theft. Switzer said most of the affected customers are residents of Ohio. Nationwide Health Plans sells health insurance in that state and a part of California.
In another recent data theft, retail chain owner TJ Maxx experienced a hack of its computer systems in December in which customer credit card information was stolen. TJ Maxx owns 751 Marshalls, 826 TJ Maxx, and 251 Homegoods stores in the United States
The Cyber Security Industry Association is pushing for a bill to require stricter management of personal identity information by businesses.
How Enterprises Are Attacking the IT Security EnterpriseTo learn more about what organizations are doing to tackle attacks and threats we surveyed a group of 300 IT and infosec professionals to find out what their biggest IT security challenges are and what they're doing to defend against today's threats. Download the report to see what they're saying.
Infographic: The State of DevOps in 2017Is DevOps helping organizations reduce costs and time-to-market for software releases? What's getting in the way of DevOps adoption? Find out in this InformationWeek and Interop ITX infographic on the state of DevOps in 2017.
Digital Transformation Myths & TruthsTransformation is on every IT organization's to-do list, but effectively transforming IT means a major shift in technology as well as business models and culture. In this IT Trend Report, we examine some of the misconceptions of digital transformation and look at steps you can take to succeed technically and culturally.