NM Insurance Bulletin 2024-004

CYBER ATTACK DATA CALL

Year: 2024Length: 819 wordsOfficial source
STATE OF NEW MEXICO OFFICE OF SUPERINTENDENT OF INSURANCE SUPERINTENDENT OF INSURANCE DEPUTY SUPERINTENDENT Alice T. Kane Colin Baillio Main Office: 1120 Paseo de Peralta, Fourth Floor, Santa Fe, NM 87501 Satellite Office: 6200 Uptown Blvd NE, Suite 400, Albuquerque, NM 87110 Main Phone: (505) 827-4601 | Toll Free: (855) 4 - ASK - OSI www.osi.state.nm.us BULLETIN 2024-004 March 6, 2024 TO: ALL MAJOR MEDICAL HEALTH INSURANCE CARRIERS AND PHARMACY BENEFIT MANAGERS OPERATING IN NEW MEXICO RE: CYBER ATTACK DATA CALL The Office of Superintendent of Insurance is aware of the February 21, 2024, cyberattack on Change Healthcare, which has impacted health care operations nationwide. Though some entities have voluntarily notified the OSI of how this is impacting New Mexico residents, the responses received have not provided an accurate scope of the impact of this attack. Pursuant to the Superintendent’s authority under NMSA § 59A-4-3, which authorizes the OSI to “direct an inquiry to any person subject to supervision under the Insurance Code,” the OSI is requesting that the major medical carriers and pharmacy benefit managers licensed to operate in New Mexico provide the following information, via email to Cass.Brulotte@osi.nm.gov and Viara.Ianakieva@osi.nm.gov within seven (7) days. Please be advised that this inquiry, and all responses, are deemed confidential in accordance with NMSA § 14-2-1 (J). This means the information provided shall not be disclosed under the Inspection of Public Records Act. The information requested below is aligned with the notification requirements found in the NAIC Insurance Data Security Model Law. 1. Provide a copy of the carrier or pharmacy benefit manager’s cyberattack incident response plan. a. Identify which subsidiaries utilize the incident response plan. b. Identify which subsidiaries are not required to adhere to the incident response plan, and why. B U L L E T I N 2 0 2 4 - 0 0 4 P a g e | 2 Main Office: 1120 Paseo de Peralta, Fourth Floor, Santa Fe, NM 87501 Satellite Office: 6200 Uptown Blvd NE, Suite 400, Albuquerque, NM 87110 Main Phone: (505) 827-4601 | Toll Free: (855) 4 - ASK - OSI www.osi.state.nm.us 2. Date of any Cybersecurity Event impacting the carrier or pharmacy benefit manager in the previous thirty (30) days. 3. Did the Cybersecurity event originate from the subject entity, a subsidiary, or a third-party vendor? 4. Description of how the information was exposed, lost, stolen, or breached, including the specific roles and responsibilities of Third-Party Service Providers, if any; 5. How the Cybersecurity Event was discovered; 6. Whether any lost, stolen, or breached information has been recovered and if so, how this was done; 7. The identity of the source of the Cybersecurity Event; 8. Whether the subject entity has filed a police report or has notified any regulatory, government or law enforcement agencies and, if so, when such notification was provided; 9. Description of the specific types of information acquired without authorization. Specific types of information means particular data elements including, for example, types of medical information, types of financial information or types of information allowing identification of the Consumer; 10. The period during which the Information System was compromised by the Cybersecurity Event; 11. The entity’s best estimate of the number of total Consumers in New Mexico affected by the Cybersecurity Event. 12. Does the entity utilize the EDGE Server? a. If so, has EDGE been impacted by the cyberattack? 13. Does the entity anticipate that this will impact SOPA reconciliation? a. If yes, provide details. 14. The results of any internal review identifying a lapse in either automated controls or internal procedures, or confirming that all automated controls or internal procedures were followed. 15. Description of efforts being undertaken to remediate the situation which permitted the Cybersecurity Event to occur. 16. A copy of the entity’s privacy policy and a statement outlining the steps the entity will take to investigate and notify New Mexico Consumers affected by the Cybersecurity Event. B U L L E T I N 2 0 2 4 - 0 0 4 P a g e | 3 Main Office: 1120 Paseo de Peralta, Fourth Floor, Santa Fe, NM 87501 Satellite Office: 6200 Uptown Blvd NE, Suite 400, Albuquerque, NM 87110 Main Phone: (505) 827-4601 | Toll Free: (855) 4 - ASK - OSI www.osi.state.nm.us 17. Name, title, and contact information of a contact person who is both familiar with the Cybersecurity Event and authorized to act for the Entity. 18. Copies of any notifications that have been sent to New Mexico consumers, providers, or producers impacted by the cyberattack. Accordingly, every major medical health insurance carrier and pharmacy benefit manager authorized the Office of Superintendent of Insurance to operated in New Mexico shall respond to the above questions no later than Wednesday, March 13, 2024 at 5:00 p.m. Any questions should be directed to Cass Brulotte at cass.brulotte@osi.nm.gov. ISSUED this 6th day of March, 2024. __________________________________ ALICE T. KANE Superintendent of Insurance
NM Insurance Bulletin 2024-004: CYBER ATTACK DATA CALL | Justis AI