This spring, as other health insurers including Anthem and Premera were announcing huge cyber attacks, CareFirst contracted with security firm Mandiant to conduct an end-to-end examination of its IT environment and the breach was found, CareFirst acknowledged on May 20.
David Holtzman, vice president of compliance at CynergisTek, a health information consultancy, praises the insurer for taking another look at their security posture after gaining knowledge of the Anthem and Premera hacks, which included programming and processes consistent with what CareFirst noticed in the spring of 2014. But security veteran Tom Walsh, president of Tom Walsh Consulting in Overland Park, Kan., has a different take: Eleven months later, they finally begin to realize there still are issues out there.