Notice of Fortra Data Security Incident
NationsBenefits provides supplemental benefits administration services to certain healthcare plans. We were recently one of many organizations impacted by a cybersecurity attack at Fortra, LLC (Fortra)—a third party vendor we used to exchange files with some of our health plan customers. The incident impacted some health plan members’ personal information, but did not disrupt any of NationsBenefits’ supplemental benefits administration operations. This notice explains the incident, the measures we have taken in response and the steps individuals can take to protect their personal information.
On or around January 30, 2023, Fortra experienced a data security incident in which a malicious actor(s) accessed or acquired the data of multiple organizations, including NationsBenefits. When we learned of this incident on February 7, 2023, we immediately took steps to secure our systems and launched an investigation, which was conducted by an experienced outside law firm and a leading cybersecurity firm. As part of our investigation, we analyzed the impacted data to determine whether any individual’s personal information was subject to unauthorized access or acquisition. Beginning on or around February 13, 2023, we confirmed that, unfortunately, certain members’ personal information was affected by the incident.
The information involved in the incident included the following data elements of some health plan members: name, demographic information (including address, phone number, gender, date of birth), phone number, health insurance number, medical ID number, Social Security number, date of service, medical device or product purchased and provider/care giver name. Importantly, not every impacted individual had all of these data elements impacted, or the same combination of data elements impacted.
Data privacy and security are among our highest priorities, and we have extensive measures in place to protect information entrusted to us. Upon discovering the incident, we immediately took steps to mitigate the risk to our impacted clients and the personal information of their members. We stopped using Fortra’s software and worked with experienced legal counsel and a leading cybersecurity firm to conduct a comprehensive investigation of the incident. We also notified law enforcement authorities and are cooperating with their investigation. To help prevent similar incidents from happening in the future, we have implemented and are continuing to implement additional procedures to further strengthen the security of our IT system environments.
Individuals should remain vigilant against incidents of identity theft and fraud, review account statements, and monitor their free credit reports for suspicious activity and to detect errors. Individuals can obtain a free copy of their credit report online at www.annualcreditreport.com, by calling toll-free (877) 322-8228, or by mailing an Annual Credit Report Request Form (available at www.annualcreditreport.com) to: Annual Credit Report Request Service, P.O. Box 105281, Atlanta, GA, 30348-5281.
We are providing notice of Fortra’s incident to affected individuals. We have also established a hotline to address questions related to this incident, which impacted individuals can reach at 1-866-313-7993. The hotline operating hours are Monday through Friday between 9:00 a.m. and 9:00 p.m. Eastern Time, excluding major U.S. holidays.
We regret that this incident occurred and any concern it may cause. We take the confidentiality and security of medical and personal information very seriously and will continue to take steps to prevent a similar incident from occurring in the future.