Feds warned Premera about security flaws before breach

  • By Mike Baker The Seattle Times
  • Thursday, March 19, 2015 8:58am
  • Business

SEATTLE — Three weeks before hackers infiltrated Premera Blue Cross, federal auditors warned the company that its network security procedures were inadequate.

Officials gave 10 recommendations for Premera to fix problems, saying some of the vulnerabilities could be exploited by hackers and expose sensitive information. Premera received the audit findings on April 18 last year, according to federal records.

The company disclosed Tuesday that a breach occurred on May 5, potentially exposing Social Security numbers, addresses, bank-account information, medical information and more for 11 million customers.

Premera didn’t respond to the audit findings until June 30 and said at the time it had made some changes and planned to implement others before the end of 2014. The company, based in Mountlake Terrace, said it didn’t discover the breach until January of this year and didn’t disclose it until this week so it could secure its information technology systems first.

Premera spokesman Eric Earling said the audit, conducted by the U.S. Office of Personnel Management, was routine. He said the company worked to address the issues raised and that the vulnerabilities described in the audit may not have been exploited by the hackers.

“We believe the questions OPM raised in their routine audit are separate from this sophisticated cyberattack,” Earling said. He declined to discuss details of the hack, citing an ongoing FBI investigation.

In one part of the technology audit, federal officials conducted vulnerability scans and found that Premera wasn’t implementing critical patches and other software updates in a timely manner.

“Failure to promptly install important updates increases the risk that vulnerabilities will not be remediated and sensitive data could be breached,” the auditors wrote.

Premera responded to the auditors by saying it would start using procedures to properly update its software. But the company told the audit team that it felt it was in compliance when it came to managing “critical security patches.”

The auditors responded that the vulnerability scans indicated the company was not in compliance with that aspect. They suggested that the company provide evidence that it had implemented the recommendation, although the documents don’t say whether that occurred.

The auditors also found that several servers contained software applications so old that they were no longer supported by the vendor and had known security problems, that servers contained “insecure configurations” that could grant hackers access to sensitive information, and that the company needed better physical controls to prevent unauthorized access to its data center.

Federal auditors examined Premera because it is one of the insurance carriers that participates in the Federal Employees Health Benefits Program. Auditors examined applications used to manage claims from federal workers, but also the company’s larger IT infrastructure.

Susan Ruge, associate counsel to the inspector general at the Office of Personnel Management, said the office is monitoring the situation at Premera, but hasn’t determined whether the data breach will lead to any unplanned audit work at the company.

Premera Blue Cross is the largest health-insurance provider in Washington state based on enrollment, and it has more than 6 million current and former customers in the state who could be affected by the breach. The company said the hackers may have gained access to customer information dating back as far as 2002.

The company is beginning to mail letters to the approximately 11 million affected customers in Washington and elsewhere.

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Business

Lily Lamoureux stacks Weebly Funko toys in preparation for Funko Friday at Funko Field in Everett on July 12, 2019.  Kevin Clark / The Herald)
Everett-based Funko: ‘Serious doubt’ it can continue without new owner or funding

The company made the statements during required filings to the SEC. Even so, its new CEO outlined his plan for a turnaround.

A runner jogs past construction in the Port of Everett’s Millwright District on Tuesday, July 15, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
Port of Everett finalizes ‘conservative’ 2026 budget

Officials point to fallout from tariffs as a factor in budget decisions.

The Verdant Health Commission holds a meeting on Oct. 22, 2025 in Lynnwood, Washington. (Olivia Vanni / The Herald)
Verdant Health Commission to increase funding

Community Health organizations and food banks are funded by Swedish hospital rent.

Sound Sports Performance & Training owner Frederick Brooks inside his current location on Oct. 30, 2025 in Lynnwood, Washington. (Olivia Vanni / The Herald)
Lynnwood gym moves to the ground floor of Triton Court

Expansion doubles the space of Sound Sports and Training as owner Frederick Brooks looks to train more trainers.

The entrance to EvergreenHealth Monroe on Monday, April 1, 2019 in Monroe, Wash. (Andy Bronson / The Herald)
EvergreenHealth Monroe buys medical office building

The purchase is the first part of a hospital expansion.

The new T&T Supermarket set to open in November on Oct. 20, 2025 in Lynnwood, Washington. (Olivia Vanni / The Herald)
TT Supermarket sets Nov. 13 opening date in Lynnwood

The new store will be only the second in the U.S. for the Canadian-based supermarket and Asian grocery.

Judi Ramsey, owner of Artisans, inside her business on Sept. 22, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
Artisans PNW allows public to buy works of 100 artists

Combo coffee, art gallery, bookshop aims to build business in Everett.

Helion's 6th fusion prototype, Trenta, on display on Tuesday, July 9, 2024 in Everett, Washington. (Olivia Vanni / The Herald)
Everett-based Helion receives approval to build fusion power plant

The plant is to be based in Chelan County and will power Microsoft data centers.

The Port of Everett’s new Director of Seaport Operations Tim Ryker on Oct. 14, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
Port of Everett names new chief of seaport operations

Tim Ryker replaced longtime Chief Operating Officer Carl Wollebek, who retired.

The Lynnwood City Council listens to a presentation on the development plan for the Lynnwood Event Center during a city council meeting on Oct. 13, 2025 in Lynnwood, Washington. (Olivia Vanni / The Herald)
Lynnwood City Council approves development of ‘The District’

The initial vision calls for a downtown hub offering a mix of retail, events, restaurants and residential options.

Everly Finch, 7, looks inside an enclosure at the Reptile Zoo on Aug. 19, 2025 in Monroe, Washington. (Olivia Vanni / The Herald)
Monroe’s Reptile Zoo to stay open

Roadside zoo owner reverses decision to close after attendance surge.

Trade group bus tour makes two stops in Everett

The tour aimed to highlight the contributions of Washington manufacturers.

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.