Bupa Global Admits Data Breach Of Health Insurance Information

Personal information has been compromised after private health insurance firm Bupa Global admitted a data breach.

The leaked information does not apparently include any medical or financial information, but it does include names, date of birth, nationality, as well as certain contact and administrative information.

Bupa Global (formerly Bupa International) said in a customer update that the data breach that it does not affect Bupa customers with local (or domestic) health insurance policies.

Sacked Staffer

Rather the breach affected those Bupa customers who have international private health insurance policies. These global policies are taken out by people who frequently travel or who work overseas.

It is thought that around 108,000 international health insurance policies are affected, and concerns users with policy numbers beginning with ‘BI’.

It seems that the firm had discovered the breach after an employee had ‘taken’ the information from some of its systems.

The staff member in question has been fired and Bupa Global is taking legal action against them.

We recently discovered an employee of our international health insurance division (which is called ‘Bupa Global’), had inappropriately copied and removed some customer information from the company,” explained Sheldon Kenton, MD of Bupa Global.

“Customers of Bupa’s local (domestic) health insurance businesses are not affected, and not all of the Bupa Global division’s 1.4 million international health insurance customers are affected,” he added.

He explained that the firm is contacting those customers affected to apologise and advise them as they believe the information has been made available to other parties.

“Protecting the information we hold about our customers is an absolute priority and I would like to assure customers that we are treating this seriously and taking steps to address the situation,” he added.

“This was not a cyber attack or external data breach, but a deliberate act by an employee,” he said. “We have introduced additional security measures and increased our customer identity checks. A thorough investigation is underway and we have informed the FCA and Bupa’s other UK regulators.”

Medical Breaches

Data breaches within the healthcare market are nothing particularly new. Indeed, the NHS has one of the worst reputations when it comes to protecting customer data.

This is after numerous incidents and complaints about the NHS handling of personal data over the past few years.

Last month the Information Commissioner’s Office (ICO) fined Basildon Council £150,000 for publishing the personal information of a family online, which included information about their mental health and disabilities.

And earlier this year the regulator also handed out a £150,000 fine to Royal & Sun Alliance Insurance (RSA) after it lost a hard drive containing the personal information of nearly 60,000 customers.

Quiz: Are you a privacy expert?

Tom Jowitt

Tom Jowitt is a leading British tech freelancer and long standing contributor to Silicon UK. He is also a bit of a Lord of the Rings nut...

Recent Posts

Intel To Invest More Than $28 Billion In Ohio Chip Factories – Report

Troubled chip giant Intel will invest more than $28 billion to construct two new chip…

2 days ago

Apple Returns To Top 5 Smartphone Ranks In China, Amid Tim Cook Visit

In Q3 Apple rejoins ranks of top five smartphone makers in China, as government welcomes…

2 days ago

Apple Cuts Orders iPhone 16, Says Analyst

Industry supply chain analyst says Apple cut orders for the iPhone 16 for Q4 2024…

2 days ago

LinkedIn Fined €310m By Irish Data Protection Commission

Heavy fine for LinkedIn, after Irish data protection watchdog cites GDPR violations with people's personal…

3 days ago

CMA Begins Probe Into Alphabet Partnership With Anthropic

UK competition regulator begins phase one investigation into Alphabet's partnership with AI startup Anthropic

3 days ago