Blue Shield of California members hit by MOVEit breach at vision benefits vendor

Organization
Blue Shield of California
Exploit
Third-Party Data Breach
Industry
Health Insurance

Blue Shield of California notified members in November 2023 that their personal and vision benefits information had been stolen during the Clop ransomware group's mass exploitation of the MOVEit Transfer file transfer product. The compromised system belonged to MESVision, a vendor that administers vision benefits for the insurer, rather than to Blue Shield itself.

According to the insurer, attackers exploited a zero-day flaw in the vendor's MOVEit server between May 28 and May 31, 2023. MESVision identified the intrusion on August 23 and informed Blue Shield on September 1. Members were not notified until mid November, a gap of roughly eleven weeks that later featured in litigation over the incident.

Two reports filed with the U.S. Department of Health and Human Services covered 636,848 and 26,523 individuals, a combined total of 663,371, according to the HIPAA Journal. Exposed fields included names, dates of birth, addresses, Social Security numbers, subscriber, group and patient ID numbers, vision provider names, claims numbers, and vision related treatment, diagnosis and cost information.

Blue Shield said its own systems were not breached and that the exposure was limited to the vendor's MOVEit server. It offered credit monitoring and identity restoration services, opened a dedicated call center, and said the vendor had taken the server offline, engaged outside cybersecurity specialists and reported the matter to the FBI. Class action suits naming both companies followed within weeks.

Sources