Anthem Breach Prompts New York To Conduct Cybersecurity Reviews Of All Insurers

In response to the data breach at healthcare insurance provider Anthem last week, New York’s Department of Financial Services (DFS) announced today that it will “integrate regular, targeted assessments of cyber security preparedness at insurance companies as part of the department’s examination process.” The Department also plans to issue “enhanced regulations” to insurance companies based in New York, but has not yet solidified what those enhancements will be.

Encryption and multi-factor authentication may be on that list. Healthcare insurers are already subject to the Gramm-Leach-Bliley Act (GLBA) and the Health Insurance Portability and Accountability Act (HIPAA), each of which have requirements about privacy and security, but neither of which explicitly require encryption of all personally identifiable information.

Read more here.

0 replies

Leave a Reply

Want to join the discussion?
Feel free to contribute!

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.