Vendor breach at Healthmine exposed Arkansas Blue Cross member data

Organization
Arkansas Blue Cross and Blue Shield
Exploit
Third-Party Data Breach
Industry
Health Insurance

Arkansas Blue Cross and Blue Shield told members in October 2024 that their personal information had been exposed through a breach at Healthmine, the vendor that hosts the portal for its Blue Wellness Rewards program.

Healthmine discovered on August 26, 2024 that an unknown party had reached the portal and used it to redeem digital gift cards. The insurer said the information that could have been viewed included names, addresses, email addresses, dates of birth and prescription histories. It stated that Social Security numbers and financial information were not involved.

Healthmine disabled the affected Rewards accounts and blocked internet domains believed to have been used to reach the portal. Arkansas Blue Cross engaged a forensic firm, contacted law enforcement and said further safeguards were being introduced, including multifactor authentication at registration and revised procedures for redeeming rewards and updating member details.

The insurer wrote to affected members and offered a complimentary one-year Experian IdentityWorks membership covering credit monitoring, identity restoration and up to $1 million in identity theft insurance. Arkansas Blue Cross did not give a figure for the number of people involved in its own announcement. HIPAA Journal reported that the incident was posted to the federal breach portal run by the Department of Health and Human Services Office for Civil Rights as affecting 633 individuals.

Sources