---
title: Insurance Companies Need Strong Security Policies - and Technology
description: Aside from the obvious reasons why they need to protect against security breaches, health insurers also need to be concerned with regulations that address security issues, namely HIPAA and HITECH Act.
image: https://businessinsights.bitdefender.com/hs-fs/file-2509017270-jpg/Blog_pics/Insurance__Security_Policies_edited.jpg
---

[![](https://businessinsights.bitdefender.com/hubfs/2021/09/logo-white.svg)](https://businessinsights.bitdefender.com/?hsLang=en-us)

[![CONTACT AN EXPERT](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd)

- [For Home](https://www.bitdefender.com/solutions/)
- [For Business](https://www.bitdefender.com/business/)
- [Resources](https://www.bitdefender.com/business/resource-library.html)
- [Webinars](https://www.bitdefender.com/business/webinars.html)

# [BUSINESS INSIGHTS](https://businessinsights.bitdefender.com/?hsLang=en-us)

[#IT Compliance & Regulations](https://businessinsights.bitdefender.com/topic/it-compliance-regulations)

 By [**Robert Krauss**](https://businessinsights.bitdefender.com/author/robert-krauss) / Feb 17, 2015

# Insurance Companies Need Strong Security Policies - and Technology

Share this [![Share on email](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/email-color.png)](mailto:?subject=Check%20out%20https://businessinsights.bitdefender.com/insurance-companies-need-strong-security-policies-and-technology&utm_medium=social&utm_source=email%20&body=Check%20out%20https://businessinsights.bitdefender.com/insurance-companies-need-strong-security-policies-and-technology&utm_medium=social&utm_source=email) [![Share on twitter](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/twitter-color.png)](https://twitter.com/intent/tweet?original_referer=https://businessinsights.bitdefender.com/insurance-companies-need-strong-security-policies-and-technology&utm_medium=social&utm_source=twitter&url=https://businessinsights.bitdefender.com/insurance-companies-need-strong-security-policies-and-technology&utm_medium=social&utm_source=twitter&source=tweetbutton&text=) [![Share on linkedin](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/linkedin-color.png)](http://www.linkedin.com/shareArticle?mini=true&url=https://businessinsights.bitdefender.com/insurance-companies-need-strong-security-policies-and-technology&utm_medium=social&utm_source=linkedin) [![Share on facebook](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/facebook-color.png)](http://www.facebook.com/share.php?u=https://businessinsights.bitdefender.com/insurance-companies-need-strong-security-policies-and-technology&utm_medium=social&utm_source=facebook)

Many insurance companies are offering coverage for data breaches, and indeed a growing number of organizations are purchasing this type of insurance as hacker attacks become more common.

Data breach or cyber insurance policies are becoming a more vital component of organizations’ preparedness plans, according to [a 2014 report by the Ponemon Institute](http://www.experian.com/assets/data-breach/brochures/2014-ponemon-2nd-annual-preparedness.pdf). In 2013 only 10% of the companies surveyed by Ponemon said they purchased a policy. In 2014, the percentage more than doubled to 26%.

As the firm noted in its [2014 Cost of Data Breach: Global Analysis](http://www.ponemon.org/blog/ponemon-institute-releases-2014-cost-of-data-breach-global-analysis), “an interesting finding is the important role cyber insurance can play in not only managing the risk of a data breach but in improving the security posture of the company. While it has been suggested that having insurance encourages companies to slack off on security, our research suggests the opposite. Those companies with good security practices are more likely to purchase insurance.”

But let’s not forget that insurance carriers themselves can be—and often are—the victims of cyber security attacks.

[One very recent and glaring example is Anthem](https://businessinsights.bitdefender.com/anthem-breached-by-remote-attack-80-million-records-at-risk?hsLang=en-us), one of the largest health insurers in the United States. The company in early February revealed that it had been hacked, resulting in the exposure of personal information about millions of its employees and members.

The attack was reported to be one of the biggest data breaches ever at a major insurance company. While the number of records lost isn’t clear, the company said all of its product lines were affected. The breach impacted Blue Cross and Blue Shield plans that are not owned by Anthem, according to an [FAQ on the company’s Web site](https://www.anthemfacts.com/faq).

The Blue Cross and Blue Shield Association's BlueCard is a national program that allows members of one Blue Cross and Blue Shield Plan to obtain healthcare services while traveling or living in another Blue Cross and Blue Shield Plan's service area, Anthem says. The program connects participating healthcare providers with the independent Blue Cross and Blue Shield Plans across the country and in more than 200 countries and territories worldwide through a single electronic network for claims processing and reimbursement.

So it’s easy to see how the breach has the potential to be in the high tens of millions of records, and how many people might be affected by the incident in one way or another.

![Insurance_Security_Policies](https://businessinsights.bitdefender.com/hs-fs/file-2509017270-jpg/Blog_pics/Insurance__Security_Policies_edited.jpg "Insurance_Security_Policies")

In an email message to members, the company’s president and CEO Joseph Swedish said the data includes individual’s names, birthdays, social security numbers, street addresses, email addresses and employment information such as income data. Based on what the company knows, there’s no evidence that credit card or medical information, such as claims, test results or diagnostic codes were targeted or compromised, the note says.

Anthem has retained a cyber security firm to evaluate its systems and identify solutions based on the “evolving landscape”.

Insurers in general are potential cyber attack targets because of the huge volumes of personal information they store and transmit. Like banks and other financial services companies, insurers rely on customers providing them with information about personal income. They also routinely gather data such as credit card numbers, social security numbers, addresses, etc.

And among criminals, healthcare insurers such as Anthem might be particularly attractive targets. As security site CSOOnline.com points out in a [recent article](http://www.csoonline.com/article/2881296/business-continuity/hackers-target-health-care-as-industry-goes-digital.html), “with more health providers and insurers incorporating IT into clinical care, hackers are viewing the healthcare industry as their next target.”

Health insurance companies use electronic health records (EHRs) and manage and store other personal data such as credit card details, the article notes.

Aside from the obvious reasons why they need to protect against security breaches, health insurers also need to be concerned with regulations that address security issues, namely the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health (HITECH) Act.

To comply with these regulations, health insurers and others in the industry have had to be extremely vigilant about protecting patient information. The laws include provisions for safeguarding protected health information (PHI) such as names, addresses, medical conditions and treatments, and the fines for non-compliance can be substantial.

Furthermore, companies can suffer long-term damage to their reputations if they are found to be in non compliance and experience a data breach.

All of this adds up to opportunities for channel partners to help clients in the insurance industry to better protect themselves against hackers, malware, denial-of-service, advanced persistent threats and other attacks.

**PAPERS YOU MIGHT BE INTERESTED IN:**

[![HIPAA compliance: what you need to know about security for virtualization and cloud environments](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/341979/afedfce3-8a6a-4cb2-ad36-3dfc3bc4fd6d.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/341979/afedfce3-8a6a-4cb2-ad36-3dfc3bc4fd6d)

[![How to address PCI compliance, security and performance in the datacenter ](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/341979/3f6757e9-3e37-46d8-8810-7bde3a130a9a.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/341979/3f6757e9-3e37-46d8-8810-7bde3a130a9a)

### Explore More Topics

- [Enterprise Security (743)](https://businessinsights.bitdefender.com/topic/enterprise-security)
- [Threat Research (201)](https://businessinsights.bitdefender.com/topic/threat-research)
- [Cloud Security (174)](https://businessinsights.bitdefender.com/topic/cloud-security)
- [SMB Security (170)](https://businessinsights.bitdefender.com/topic/smb-security)
- [Ransomware (166)](https://businessinsights.bitdefender.com/topic/ransomware)
- [Privacy and Data Protection (137)](https://businessinsights.bitdefender.com/topic/privacy-and-data-protection)
- [Cybersecurity Awareness (134)](https://businessinsights.bitdefender.com/topic/cybersecurity-awareness)
- [Endpoint Protection & Management (126)](https://businessinsights.bitdefender.com/topic/endpoint-protection-management)
- [Endpoint Detection and Response (124)](https://businessinsights.bitdefender.com/topic/endpoint-detection-and-response)
- [Managed Detection and Response (119)](https://businessinsights.bitdefender.com/topic/managed-detection-and-response)
- [Virtualization & Data Center Security (82)](https://businessinsights.bitdefender.com/topic/virtualization-data-center-security)
- [Threat Intelligence (76)](https://businessinsights.bitdefender.com/topic/threat-intelligence)
- [IT Compliance & Regulations (71)](https://businessinsights.bitdefender.com/topic/it-compliance-regulations)
- [Bitdefender Threat Debrief (55)](https://businessinsights.bitdefender.com/topic/bitdefender-threat-debrief)
- [Managed Service Providers (53)](https://businessinsights.bitdefender.com/topic/managed-service-providers)
- [#Featured (52)](https://businessinsights.bitdefender.com/topic/featured)
- [Advanced Persistent Threats (46)](https://businessinsights.bitdefender.com/topic/advanced-persistent-threats)
- [Events (38)](https://businessinsights.bitdefender.com/topic/events)
- [Independent Testing (18)](https://businessinsights.bitdefender.com/topic/independent-testing)
- [Cybersecurity Advisory Services (9)](https://businessinsights.bitdefender.com/topic/cybersecurity-advisory-services)
- [Podcast (3)](https://businessinsights.bitdefender.com/topic/podcast)
- [top (2)](https://businessinsights.bitdefender.com/topic/top)

See all topics

### Subscribe to Blog Updates

## Read more about this topic

<https://businessinsights.bitdefender.com/healthcare-industry-in-need-of-security-medicine?hsLang=en-us>

### [Healthcare Industry: In Need of Security Medicine](https://businessinsights.bitdefender.com/healthcare-industry-in-need-of-security-medicine?hsLang=en-us)

<https://businessinsights.bitdefender.com/the-internet-wants-you-consider-a-career-in-cybersecurity?hsLang=en-us>

### [The Internet Wants You: Consider a Career in Cybersecurity](https://businessinsights.bitdefender.com/the-internet-wants-you-consider-a-career-in-cybersecurity?hsLang=en-us)

<https://businessinsights.bitdefender.com/are-healthcare-organizations-doing-enough-to-ensure-security?hsLang=en-us>

### [Are Healthcare Organizations Doing Enough to Ensure Security?](https://businessinsights.bitdefender.com/are-healthcare-organizations-doing-enough-to-ensure-security?hsLang=en-us)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2685110570-png/Bitdefender-Mar2015-Theme/Images/avatar_img_footer.png)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2676149282-png/Bitdefender-Mar2015-Theme/Images/logo_white_footer.png)

- [![https://twitter.com/Bitdefender_Ent](https://businessinsights.bitdefender.com/hs-fs/file-2658233851-png/Bitdefender-Mar2015-Theme/Images/ft_soc_tw.png?width=33&name=ft_soc_tw.png)](https://twitter.com/Bitdefender_Ent)
- [![Linkedin-icon-300x300](https://businessinsights.bitdefender.com/hs-fs/hubfs/Bitdefender-Mar2015-Theme/Images/Linkedin-icon-300x300.png?width=33&name=Linkedin-icon-300x300.png)](https://www.linkedin.com/company/bitdefender-gravityzone-enterprise-security)
- [![](https://businessinsights.bitdefender.com/hs-fs/file-2676149307-png/Bitdefender-Mar2015-Theme/Images/ft_soc_yt.png)](https://www.youtube.com/user/BitdefenderSecurity)

- [Legal Terms](https://www.bitdefender.com/legal/)
- [Privacy Policy](https://www.bitdefender.com/site/view/legal-privacy-policy-for-bitdefender-websites.html)
- [EULA](https://www.bitdefender.com/site/view/legal-eula.html)
- [Contact Us](https://www.bitdefender.com/business/contact.html)

Copyright © 1997-2023 Bitdefender All rights reserved.

![](https://px.spiceworks.com/px/5rec)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Robert Krauss",
    "url" : "https://businessinsights.bitdefender.com/author/robert-krauss"
  },
  "datePublished" : "2015-02-17T15:55:00.000Z",
  "headline" : "Insurance Companies Need Strong Security Policies - and Technology",
  "image" : [ "https://businessinsights.bitdefender.com/hs-fs/file-2509017270-jpg/Blog_pics/Insurance__Security_Policies_edited.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://businessinsights.bitdefender.com/insurance-companies-need-strong-security-policies-and-technology",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://businessinsights.bitdefender.com/hubfs/Bitdefender_Logo_Transparent-2.png"
    },
    "name" : "Bitdefender"
  }
}
```