Stethoscope on table showing health insurance data breach

WebTPA Health Insurance Data Breach Leaks 2.4 Million Members’ Sensitive Information

WebTPA Employer Services has notified the U.S. Department of Health and Human Services (HHS) of a massive data breach that leaked the personal information of over 2.4 million health insurance plan members.

The Irvin, Texas-based third-party administrator (TPA) is a subsidiary of GuideWell Mutual Holding Corporation. It provides administrative services to certain benefit plans and insurance companies.

WebTPA customers include the Allied Pilots Association, Dean Health Plan, Gerber Life Insurance Company, Hartford Insurance, and Transamerica Life Insurance Company. Several insurance companies have confirmed being victims of the WebTPA data breach.

Health insurance firm WebTPA’s data breach leaked sensitive information

According to a statement on its website, WebTPA said it detected a “data security incident” affecting certain systems on December 28, 2023.

The health insurance administrator responded by initiating mitigation measures to limit the threat actor’s activity on the network.

WebTPA also launched an investigation with leading cybersecurity experts and federal law enforcement authorities. The health insurance third-party administrator has also notified relevant regulatory authorities in California, Massachusetts, and South Carolina.

According to the May 8, 2024, data breach notification letters, WebTPA’s probe determined that an “unauthorized actor may have obtained personal information between April 18 and April 23, 2023.”

The health insurance firm promptly informed benefit plans and insurance companies on March 25, 2024, disclosing the likelihood of exposure of personal information.

Although potentially exposed personal information varied among individuals, it likely included name, contact information, date of birth, date of death, Social Security number, and insurance information.

“Social security numbers appear to be the main mandatory information that WebTPA has on its consumers, which were exposed during the hack,” said Narayana Pappu, CEO at Zendata. “Assuming it is a complete social security number (all nine digits vs. last 4), hackers can combine social security numbers with DOBs to apply for new credit, open bank accounts, or perform elaborate schemes, such as SIM swapping.”

However, the WebTPA data breach did not expose the victims’ financial information, such as bank account details or credit card numbers, or the victims’ treatment or diagnostic information.

So far, WebTPA has no evidence that the threat actor has misused the stolen information. However, the health insurance administrator is offering 24 months of complimentary identity monitoring services via Kroll to protect victims from identity theft or fraud.

The third-party health insurance administrator has also implemented additional security measures and tools to bolster its network security.

WebTPA also advised the victims to remain vigilant by reviewing their credit reports and monitoring their benefit plans for suspicious activity. Victims could also place credit freezes and fraud alerts to prevent fraudsters from opening new credit lines.

Nonetheless, WebTPA has only shared limited details regarding the year-old data breach, including why it took so long to notify the victims. Little is known about the threat actor or the attack vector exploited in the WebTPA data breach.

Usually, a more detailed data breach report suggests that a comprehensive investigation was carried out and signals the company’s commitment to transparency and willingness to rebuild trust with the impacted victims.

Health insurance provider facing data breach lawsuits

Meanwhile, the health insurance administrator faces numerous lawsuits for allegedly failing to protect personal information in its possession.

One lawsuit alleges that WebTPA “lost control,” enabling the threat actor to gain “unfettered access” to its current and former customers’ information for more than eight months before discovering the “suspicious activity.”

Meanwhile, cybercriminals continue to target healthcare organizations to disrupt clinical operations and access sensitive personal and health information.

“Companies that are the custodians of critical healthcare information require a much higher bar for security and monitoring than other types of organizations,” said Darren Guccione, CEO and Co-Founder at Keeper Security.

Halfway into 2024, Change Healthcare, Ascension Healthcare Systems, and Australian electronic prescription provider MediSecure have experienced ransomware attacks.

“While not every attack can be prevented, steps can be taken to mitigate the access of cybercriminals and minimize impacts on systems, data and operations,” concluded Guccione. “The most effective method for minimizing sprawl if an attack does occur is by investing in prevention with a zero-trust and zero-knowledge cybersecurity architecture that will limit, if not altogether prevent, a bad actor’s access.”