Contact Tracing Breach In Pennsylvania Impacts Private Information Of 72,000 People

HARRISBURG, Pa. (AP) — Employees of a vendor paid to conduct COVID-19 contact tracing in Pennsylvania may have compromised the private information of at least 72,000 people, including their exposure status and their sexual orientation, the state Health Department said Thursday.

Agency spokesman Barry Ciccocioppo said in an email it recently learned workers at Atlanta-based Insight Global "disregarded security protocols established in the contract and created unauthorized documents" outside the state's secure data system.

"We are extremely dismayed that employees from Insight Global acted in a way that may have compromised this type of information and sincerely apologize to all impacted individuals," Ciccocioppo said. He said state computer systems, including Pennsylvania's contact tracing app, were not implicated.

The state Treasury Department said Insight Global has been paid about $28.7 million since March 2020.

Ciccocioppo said some of the records in question associated names with phone numbers, emails, genders, ages, sexual orientations and COVID-19 diagnoses and exposure status. They did not include financial account information, addresses or Social Security numbers, he said.

The company has been directed to secure the records and has hired third-party specialists to conduct a forensic examination.

State lawmakers were briefed on the problem Thursday morning. House Majority Leader Kerry Benninghoff, R-Centre, called it an "incredibly careless and damaging breach of trust."

"This latest example of gross mismanagement by the Wolf administration speaks volumes to the dangers of unchecked, unilateral executive authority and why the people's voice through their elected representatives and senators needs to be heard during challenging times," Benninghoff said.

He said the state's agreement with Insight Global was not competitively bid. About 900 Insight Global employees have been involved in contact tracing in the state, according to the Health Department.

The Department of Health's emergency contract with Insight Global required the staffing agency to safeguard people's data and, in the event of "any improper disclosure of information," to provide credit monitoring and other remedies. It also required Insight Global to comply with federal health privacy law.

Insight Global "recognizes and accepts that the contact tracing workforce will have access to personal health information of contact tracing subjects and must ensure that and all other such information related to the services being provided must be kept confidential and secure," according to a contract addendum.

Ciccocioppo said some of the records in question associated names with phone numbers, emails, genders, ages, sexual orientations and COVID-19 diagnoses and exposure status. They did not include financial account information, addresses or Social Security numbers, he said.

The state's health department won't renew the contract with Insight Global that expires in three months. The company will be notifying people affected by the data breach and will open a daytime hotline starting Friday afternoon for anyone concerned they might have been involved. That number is 855-535-1787.

Free credit monitoring and identity protection services will be offered.

Insight Global, which started a health care division during the pandemic and bills itself as a "leading talent solutions firm," was under pressure to scale up quickly. The company had to hire 250 contact tracers within 35 days, then bring on additional workers every two weeks until the effort was fully staffed.

(Copyright 2021 The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.)

Read more
f

We and our partners use cookies to understand how you use our site, improve your experience and serve you personalized content and advertising. Read about how we use cookies in our cookie policy and how you can control them by clicking Manage Settings. By continuing to use this site, you accept these cookies.