As many workers compensation processes move online to fill a gap in services due to the COVID-19 pandemic, industry experts say cyberattacks are more likely, but changes to federal health information privacy rules may protect those who deal with data.
Companies working with injured workers have access to significant amounts of personal information for claimants, including health care records, addresses, Social Security numbers and other information that hackers target.
In the workers comp sector, the likelihood of a data breach often depends on the security controls a company has in place, including the security controls of third parties where information is shared, said Patrick McCrann, Cleveland-based chief information security officer at AmTrust Financial Services Inc.
“I would really look at any type of workers compensation information, whether it’s held at a corporation or with a (third-party administrator) … even with the insurance carrier, wherever that data is held, it’s incumbent upon whichever organization to make sure they’re adequately protecting it,” said Stephanie Snyder, Chicago-based senior vice president, commercial strategy leader at Aon PLC.
Access to sensitive information should also be restricted because the most common cause of data breaches is employees, she said.
“Unfortunately, humans tend to be the weakest link,” said Nikki Ingram, Schaumberg, Illinois-based cybersecurity risk engineer at Zurich North America. “It’s easier for the unsophisticated attacker to go after the human element.”
But phishing attacks, where employees typically are tricked by scam emails, can be sophisticated and targeted, she said.
“Attackers are opportunistic … they are going to use the things that are on people’s minds to try to attack people,” said Wesley McGrew, Starkville, Mississippi-based director of cyber operations for Horne Cyber, a unit of consulting firm Horne LLP. “There’s already coronavirus phishing scams and scam websites.”
Meanwhile, the recent relaxing of federal medical privacy laws that previously required technology that is compliant with security rules, such as the use of encrypted software, could protect workers compensation providers from penalties for data breaches, according to experts.
“The (telemedicine) market was in some ways restricted because these providers had to be compliant and had to ensure that the technology was consistent with (U.S. Department of Health and Human Services) mandates,” said David Katz, partner in the Atlanta office of Adams and Reese LLP.
More insurance and workers compensation news on the coronavirus crisis here.