After Health Net, Inc. in California announced Monday that several data servers containing sensitive health and personal information on its enrollees are unaccounted for, state officials said the security breach involves "personal information for 1.9 million current and past enrollees nationwide."
The California Department of Managed Health Care, the only stand-alone HMO watchdog agency in the nation, also provided further details beyond the plan's statement, saying that the missing records on nine servers are "for more than 622,000 enrollees in Health Net products regulated by the DMHC, more than 223,000 enrolled in the California Department of Insurance products (another state agency that has oversight responsibility) and a number enrolled in Medicare."
"The DMHC has opened an investigation into Health Net's security practices," said DMHC spokesperson Lynne Randolph. "Health Net has agreed to provide two years of free credit monitoring services to its California enrollees, in addition to identity theft insurance, fraud resolution and restoration of credit files, if needed."
In a statement posted on its website, Health Net did not specify the number of servers, saying only that there are "several," nor did the company specify the number of enrollees whose data may be compromised. It characterized the files as "unaccounted for." Asked if the DMHC's statement regarding the scope of the breach is accurate, Health Net spokesman Brad Kieffer says, "Our press release constitutes our statement to the media."
The Los Angeles-based health plan said the investigation "follows notification by IBM, Health Net's vendor responsible for managing Health Net's IT (information technology) infrastructure, that it could not locate several server drivers.
"Personal information of some former and current Health Net members, employees and health care providers is on the drives, and may include names, addresses, health information, Social Security numbers and/or financial information," the Health Net statement said.
Health Net says it is notifying the individuals whose information is on the drives "out of an abundance of caution."