Local: (805)-371-3680 | Toll Free: (800) 240-CHIV
Facebook
LinkedIn
Chivaroli Insurance Services
  • INSURANCE COVERAGE
    • Medical Professional Liability
    • Commercial Auto Insurance
    • Errors & Omissions Insurance
    • Commercial General Liability
    • Business Owners Policy (BOP)
    • Representations & Warranties
    • Directors’ & Officers’ Liability
    • Fiduciary Liability Insurance
    • Terrorism Risk Insurance
    • Commercial Property
    • Commercial Crime
    • Difference in Conditions
    • Workers Compensation
    • Employment Practices Liability
    • Stop Loss Insurance
    • Security & Privacy (Cyber) Liability
    • Products Liability
    • Personal Lines Insurance
  • OTHER SERVICES
    • Alternatives
    • Consulting Services
    • Credentialing Requests
    • Risk Management
    • Wholesale Brokerage
  • RESOURCES
    • Healthcare Resources
    • Insurance Resources
    • Terms & Definitions
  • NEWS
  • ABOUT
  • CONTACT

UPMC data breach could be part of a national scheme

April 30, 2014Chivaroli and Associates Insurance ServicesArticle Archives

data breachSource Pittsburgh Post-Gazette (PA)

April 19–The data breach that has compromised the personal information of thousands of UPMC employees and the tax returns of hundreds more could be part of a national scheme.

UPMC confirmed Thursday that a data breach thought to only affect a few dozen employees when announced in February has actually revealed the personal information of approximately 27,000 employees.

Among those employees, 788 have experienced some form of tax fraud and several others have had bank accounts wiped clean, according to Michael Kraemer, a Pittsburgh attorney who has filed a suit seeking class-action litigation against UPMC. The health care organization and its subsidiaries employ approximately 62,000 people.

Questions surrounding how the breach occurred and how long UPMC knew about it before alerting employees have yet to be answered, said Mr. Kraemer.

However, if UPMC were caught up in a scheme that has resulted in the filing of more than $1 million in fraudulent tax returns this year, the company may not have understood the full scale of the data breach until it was too late.

Brian Krebs, a former Washington Post cybersecurity reporter who operates the investigative blog KrebsonSecurity.com, said at least half a dozen health care providers across the nation have been targeted by cybercriminals hacking into third party vendors to access human resources or payroll records.

According to Mr. Krebs, individuals within the payroll or human resources department likely had their computers compromised by malware designed to steal their login and password credentials. Once cybercriminals had the credentials, they would access employees’ W2 records through cloud-based third-party vendors that store payroll and personnel information. The criminals then use that information to file the false returns with online tax software.

Mr. Krebs uncovered the scam in March when he came across a Web-based control panel used by criminal gangs to track individuals whose data had been used to file false returns. So far, more than six health care companies have been affected. He did not directly investigate the UPMC incident and could not say for sure if it was affected by that particular breach.

The full report on the breach can be found at: krebsonsecurity.com/2014/04/crimeware-helps-file-fraudulent-tax-returns.

UPMC spokeswoman Gloria Kreps didn’t immediately answer questions surrounding whether the organization was affected by the breach Mr. Krebs uncovered.

Once an organization discovers a common denominator is a third-party vendor, there’s no quick way to find out every Social Security number that has been compromised.

“It’s not like they can just call the IRS and ask them. If they’re working with a third-party vendor, they need to work with them to find out which records were accessed and which employees are at risk,” Mr. Krebs said.

Regardless of how far UPMC believed the investigation reached, Mr. Kraemer said erring on the side of caution could have saved employees thousands of dollars and weeks of grief. “The minute they confirmed there was a data breach, they should have mitigated the situation. A lot of people could have avoided problems if they knew to contact the IRS in advance to tell them to stop payment on the refund check,” he said.

UPMC is encouraging all of its employees to notify their banks and check with the IRS to ensure they have not had fraudulent returns filed in their name. The company also is providing LifeLock identity protection free of charge to employees who enroll in the program by April 28.

To report suspected tax fraud to the IRS, call the Tax Fraud Hotline at 1-800-829-0433 or visit www.irs.gov/Individuals/How-Do-You-Report-Suspected-Tax-Fraud-Activity%3F.

To make sure your business is protected from data breaches, contact Chivaroli & Associates.

Chivaroli and Associates Insurance Services
Chivaroli & Associates Insurance Services is a full-service brokerage and consulting firm that specializes in the custom design and placement of property and casualty insurance and alternative risk funding solutions for healthcare organizations.
Previous post Top 5 Riskiest States for Employee Lawsuits: Hiscox Next post Stolen Laptops Lead to $2 Million in HHS Fines
Sign up for Chivaroli & Associates Newsletter
* = required field
unsubscribe from list

Categories

  • Article Archives
  • General Article
  • Private
  • Uncategorized

Archives

  • February 2025
  • December 2024
  • November 2024
  • October 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • November 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • August 2019
  • July 2019
  • June 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018
  • November 2018
  • August 2018
  • July 2018
  • June 2018
  • May 2018
  • April 2018
  • March 2018
  • February 2018
  • December 2017
  • November 2017
  • October 2017
  • August 2017
  • July 2017
  • June 2017
  • May 2017
  • April 2017
  • March 2017
  • February 2017
  • January 2017
  • November 2016
  • October 2016
  • September 2016
  • August 2016
  • July 2016
  • June 2016
  • May 2016
  • April 2016
  • March 2016
  • February 2016
  • December 2015
  • November 2015
  • October 2015
  • September 2015
  • August 2015
  • July 2015
  • June 2015
  • April 2015
  • February 2015
  • January 2015
  • December 2014
  • November 2014
  • October 2014
  • September 2014
  • August 2014
  • July 2014
  • June 2014
  • May 2014
  • April 2014
  • March 2014
  • February 2014
  • January 2014

Chivaroli and Associates Insurance Services is a full-service brokerage firm specializing in the custom-design and placement of insurance and alternative risk funding solutions for your healthcare organization.

Facebook
Twitter
LinkedIn
YouTube

Contact Us Today

Address:
200 North Westlake Blvd., Suite 101
Westlake Village, CA 91362
Phone:
805-371-3680
E-mail:
mail@chivarolitr.wpengine.com

Resources

Health Care
Insurance
Terms & Definitions
News
About

Policies

Cookie Policy
Disclaimer

Recent News

  • Premium Hikes Continued in Q4 2024, Latest Survey Shows 
  • ‘Nuclear’ Medical Malpractice Verdicts on the Rise
  • Pay Now, Deliver Later: Some Women Are Prepaying for Their Baby
  • Fidelity Bonds vs. Commercial Crime Insurance: Which is Right for You?
© 2025 All rights reserved. Powered By Insurance Agency Website by Stratosphere