NM Insurance Bulletin 2024-004
CYBER ATTACK DATA CALL
STATE OF NEW MEXICO
OFFICE OF SUPERINTENDENT OF INSURANCE
SUPERINTENDENT OF INSURANCE
DEPUTY SUPERINTENDENT
Alice T. Kane Colin Baillio
Main Office: 1120 Paseo de Peralta, Fourth Floor, Santa Fe, NM 87501
Satellite Office: 6200 Uptown Blvd NE, Suite 400, Albuquerque, NM 87110
Main Phone: (505) 827-4601 | Toll Free: (855) 4 - ASK - OSI
www.osi.state.nm.us
BULLETIN 2024-004
March 6, 2024
TO:
ALL MAJOR MEDICAL HEALTH INSURANCE CARRIERS AND PHARMACY
BENEFIT MANAGERS OPERATING IN NEW MEXICO
RE:
CYBER ATTACK DATA CALL
The Office of Superintendent of Insurance is aware of the February 21, 2024, cyberattack
on Change Healthcare, which has impacted health care operations nationwide. Though some
entities have voluntarily notified the OSI of how this is impacting New Mexico residents, the
responses received have not provided an accurate scope of the impact of this attack.
Pursuant to the Superintendent’s authority under NMSA § 59A-4-3, which authorizes the
OSI to “direct an inquiry to any person subject to supervision under the Insurance Code,” the OSI
is requesting that the major medical carriers and pharmacy benefit managers licensed to operate in
New Mexico provide the following information, via email to Cass.Brulotte@osi.nm.gov and
Viara.Ianakieva@osi.nm.gov within seven (7) days.
Please be advised that this inquiry, and all responses, are deemed confidential in
accordance with NMSA § 14-2-1 (J). This means the information provided shall not be disclosed
under the Inspection of Public Records Act. The information requested below is aligned with the
notification requirements found in the NAIC Insurance Data Security Model Law.
1. Provide a copy of the carrier or pharmacy benefit manager’s cyberattack incident response
plan.
a. Identify which subsidiaries utilize the incident response plan.
b. Identify which subsidiaries are not required to adhere to the incident response plan,
and why.
B U L L E T I N 2 0 2 4 - 0 0 4
P a g e | 2
Main Office: 1120 Paseo de Peralta, Fourth Floor, Santa Fe, NM 87501
Satellite Office: 6200 Uptown Blvd NE, Suite 400, Albuquerque, NM 87110
Main Phone: (505) 827-4601 | Toll Free: (855) 4 - ASK - OSI
www.osi.state.nm.us
2. Date of any Cybersecurity Event impacting the carrier or pharmacy benefit manager in the
previous thirty (30) days.
3. Did the Cybersecurity event originate from the subject entity, a subsidiary, or a third-party
vendor?
4. Description of how the information was exposed, lost, stolen, or breached, including the
specific roles and responsibilities of Third-Party Service Providers, if any;
5. How the Cybersecurity Event was discovered;
6. Whether any lost, stolen, or breached information has been recovered and if so, how this
was done;
7. The identity of the source of the Cybersecurity Event;
8. Whether the subject entity has filed a police report or has notified any regulatory,
government or law enforcement agencies and, if so, when such notification was provided;
9. Description of the specific types of information acquired without authorization. Specific
types of information means particular data elements including, for example, types of
medical information, types of financial information or types of information allowing
identification of the Consumer;
10. The period during which the Information System was compromised by the Cybersecurity
Event;
11. The entity’s best estimate of the number of total Consumers in New Mexico affected by
the Cybersecurity Event.
12. Does the entity utilize the EDGE Server?
a. If so, has EDGE been impacted by the cyberattack?
13. Does the entity anticipate that this will impact SOPA reconciliation?
a. If yes, provide details.
14. The results of any internal review identifying a lapse in either automated controls or
internal procedures, or confirming that all automated controls or internal procedures were
followed.
15. Description of efforts being undertaken to remediate the situation which permitted the
Cybersecurity Event to occur.
16. A copy of the entity’s privacy policy and a statement outlining the steps the entity will take
to investigate and notify New Mexico Consumers affected by the Cybersecurity Event.
B U L L E T I N 2 0 2 4 - 0 0 4
P a g e | 3
Main Office: 1120 Paseo de Peralta, Fourth Floor, Santa Fe, NM 87501
Satellite Office: 6200 Uptown Blvd NE, Suite 400, Albuquerque, NM 87110
Main Phone: (505) 827-4601 | Toll Free: (855) 4 - ASK - OSI
www.osi.state.nm.us
17. Name, title, and contact information of a contact person who is both familiar with the
Cybersecurity Event and authorized to act for the Entity.
18. Copies of any notifications that have been sent to New Mexico consumers, providers, or
producers impacted by the cyberattack.
Accordingly, every major medical health insurance carrier and pharmacy benefit manager
authorized the Office of Superintendent of Insurance to operated in New Mexico shall respond to
the above questions no later than Wednesday, March 13, 2024 at 5:00 p.m. Any questions should
be directed to Cass Brulotte at cass.brulotte@osi.nm.gov.
ISSUED this 6th day of March, 2024.
__________________________________
ALICE T. KANE
Superintendent of Insurance