Feds warned Premera about security flaws before breach

  • By Mike Baker The Seattle Times
  • Thursday, March 19, 2015 8:58am
  • Business

SEATTLE — Three weeks before hackers infiltrated Premera Blue Cross, federal auditors warned the company that its network security procedures were inadequate.

Officials gave 10 recommendations for Premera to fix problems, saying some of the vulnerabilities could be exploited by hackers and expose sensitive information. Premera received the audit findings on April 18 last year, according to federal records.

The company disclosed Tuesday that a breach occurred on May 5, potentially exposing Social Security numbers, addresses, bank-account information, medical information and more for 11 million customers.

Premera didn’t respond to the audit findings until June 30 and said at the time it had made some changes and planned to implement others before the end of 2014. The company, based in Mountlake Terrace, said it didn’t discover the breach until January of this year and didn’t disclose it until this week so it could secure its information technology systems first.

Premera spokesman Eric Earling said the audit, conducted by the U.S. Office of Personnel Management, was routine. He said the company worked to address the issues raised and that the vulnerabilities described in the audit may not have been exploited by the hackers.

“We believe the questions OPM raised in their routine audit are separate from this sophisticated cyberattack,” Earling said. He declined to discuss details of the hack, citing an ongoing FBI investigation.

In one part of the technology audit, federal officials conducted vulnerability scans and found that Premera wasn’t implementing critical patches and other software updates in a timely manner.

“Failure to promptly install important updates increases the risk that vulnerabilities will not be remediated and sensitive data could be breached,” the auditors wrote.

Premera responded to the auditors by saying it would start using procedures to properly update its software. But the company told the audit team that it felt it was in compliance when it came to managing “critical security patches.”

The auditors responded that the vulnerability scans indicated the company was not in compliance with that aspect. They suggested that the company provide evidence that it had implemented the recommendation, although the documents don’t say whether that occurred.

The auditors also found that several servers contained software applications so old that they were no longer supported by the vendor and had known security problems, that servers contained “insecure configurations” that could grant hackers access to sensitive information, and that the company needed better physical controls to prevent unauthorized access to its data center.

Federal auditors examined Premera because it is one of the insurance carriers that participates in the Federal Employees Health Benefits Program. Auditors examined applications used to manage claims from federal workers, but also the company’s larger IT infrastructure.

Susan Ruge, associate counsel to the inspector general at the Office of Personnel Management, said the office is monitoring the situation at Premera, but hasn’t determined whether the data breach will lead to any unplanned audit work at the company.

Premera Blue Cross is the largest health-insurance provider in Washington state based on enrollment, and it has more than 6 million current and former customers in the state who could be affected by the breach. The company said the hackers may have gained access to customer information dating back as far as 2002.

The company is beginning to mail letters to the approximately 11 million affected customers in Washington and elsewhere.

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Business

Szabella Psaztor is an Emerging Leader. (Olivia Vanni / The Herald)
Szabella Pasztor: Change begins at a grassroots level

As development director at Farmer Frog, Pasztor supports social justice, equity and community empowerment.

Owner and founder of Moe's Coffee in Arlington Kaitlyn Davis poses for a photo at the Everett Herald on March 22, 2024 in Everett, Washington. (Annie Barker / The Herald)
Kaitlyn Davis: Bringing economic vitality to Arlington

More than just coffee, Davis has created community gathering spaces where all can feel welcome.

Simreet Dhaliwal is an Emerging Leader. (Olivia Vanni / The Herald)
Simreet Dhaliwal: A deep-seated commitment to justice

The Snohomish County tourism and economic specialist is determined to steer change and make a meaningful impact.

Emerging Leader John Michael Graves. (Ryan Berry / The Herald)
John Michael Graves: Champion for diversity and inclusion

Graves leads training sessions on Israel, Jewish history and the Holocaust and identifying antisemitic hate crimes.

Gracelynn Shibayama, the events coordinator at the Edmonds Center for the Arts, is an Emerging Leader. (Olivia Vanni / The Herald)
Gracelynn Shibayama: Connecting people through the arts and culture

The Edmonds Center for the Arts coordinator strives to create a more connected and empathetic community.

Eric Jimenez, a supervisor at Cocoon House, is an Emerging Leader. (Olivia Vanni / The Herald)
Eric Jimenez: Team player and advocate for youth

As an advocate for the Latino community, sharing and preserving its traditions is central to Jimenez’ identity.

Nathanael Engen, founder of Black Forest Mushrooms, an Everett gourmet mushroom growing operation is an Emerging Leader. (Olivia Vanni / The Herald)
Nathanael Engen: Growing and sharing gourmet mushrooms

More than just providing nutritious food, the owner of Black Forest Mushrooms aims to uplift and educate the community.

Molbak's Garden + Home in Woodinville, Washington closed on Jan. 28 2024. (Photo courtesy of Molbak's)
Molbak’s, former Woodinville garden store, hopes for a comeback

Molbak’s wants to create a “hub” for retailers and community groups at its former Woodinville store. But first it must raise $2.5 million.

DJ Lockwood, a Unit Director at the Arlington Boys & Girls Club, is an Emerging Leader. (Olivia Vanni / The Herald)
DJ Lockwood: Helping the community care for its kids

As director of the Arlington Boys & Girls Club, Lockwood has extended the club’s programs to more locations and more kids.

Alex Tadio, the admissions director at WSU Everett, is an Emerging Leader. (Olivia Vanni / The Herald)
Alex Tadio: A passion for education and equality

As admissions director at WSU Everett, he hopes to give more local students the chance to attend college.

Dr. Baljinder Gill and Lavleen Samra-Gill are the recipients of a new Emerging Business award. Together they run Symmetria Integrative Medical. (Olivia Vanni / The Herald)
Emerging Business: The new category honors Symmetria Integrative Medical

Run by a husband and wife team, the chiropractic and rehabilitation clinic has locations in Arlington, Marysville and Lake Stevens.

People walk along the waterfront in front of South Fork Bakery at the Port of Everett on Thursday, April 11, 2024 in Everett, Washington. (Olivia Vanni / The Herald)
Port of Everett inks deal with longtime Bothell restaurant

The port will break ground on two new buildings this summer. Slated for completion next year, Alexa’s Cafe will open in one of them.

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.