Healthplex Agrees to Pay $2 Million to NYDFS to Resolve Cybersecurity Failures

A New York Department of Financial Services (DFS) investigation of a 2021 phishing attack on the dental insurance management services company Healthplex has been resolved with a $2 million settlement. In November 2021, a customer service employee responded to a phishing email and disclosed their credentials, allowing their email account to be accessed. The incident was detected when employees received phishing emails from the compromised account.

The forensic investigation confirmed that the original phishing email was received by the employee on November 22 or November 23, 2021, and the threat actor used the credentials to access the employee’s Microsoft Office 365 account. The account contained the personal health information of tens of thousands of New Yorkers, including names, addresses, dates of birth, Social Security numbers, financial information, and driver’s license numbers. The DFS was notified about the phishing attack and data breach on April 8, 2022.

Credentials alone should not be enough to access an account containing sensitive data. Multifactor authentication should be implemented to provide an additional layer of protection. Organizations should also implement data retention policies to limit the amount of sensitive data in accounts to minimize the impact of a security incident should cybersecurity protections be circumvented. These measures are security best practices and also a requirement of the DFS’s Cybersecurity Regulation (23 NYCRR Part 500).

All businesses operating under a license, charter, or similar authorization from the DFS are required to comply with the Cybersecurity Regulation, including state-chartered banks, licensed lenders, and insurance companies. Those covered entities must establish and maintain a risk assessment-based cybersecurity program to protect the confidentiality, integrity, and availability of information systems and all data contained in those systems.

The DFS determined that there was no data retention policy limiting the storage of data in its email environment, which meant the threat actor was able to access 12 years of emails, and MFA had not been implemented on its Microsoft 365 email environment. While the Cybersecurity Regulation requires data breaches to be reported to the DFS within 72 hours, it took Healthplex more than four months to report the security incident

“Health insurance providers are entrusted with highly sensitive personal information and health data of policyholders,” said DFS Superintendent Adrienne Harris. “The Department’s nation-leading cybersecurity regulation requires insurers and other regulated entities to maintain and implement robust cybersecurity policies, so the private information New Yorkers entrust to them is protected. Healthplex’s failure to adhere to these rules resulted in the exposure of the sensitive data of tens of thousands of consumers.” In addition to the financial penalty, Healthplex has agreed to undergo an audit by an independent third-party audit to review its multi-factor authentication controls and will mitigate any identified issues within a reasonable timeframe.

HIPAA
Compliance
Checklist

Simple Guidelines
Immediate PDF Download

Immediate Access

Privacy Policy

Download Free Checklist

This is not the first financial penalty to be paid by Healthplex in relation to this incident. Healthplex settled an investigation by the New York Attorney General in 2023 and paid a $400,000 financial penalty to resolve alleged violations of the Health Insurance Portability and Accountability Act and state laws. The settlement agreement also included the requirement to comply with the HIPAA Rules and maintain reasonable security policies to ensure the confidentiality, integrity, and availability of protected health information. Those measures included a data retention policy ensuring data is only maintained for as long as there is a legitimate business reason for retaining the information, implementing more stringent password policies and procedures, and encrypting member information.

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/