There have been a rash of data breaches at health insurers and healthcare companies, but what makes the hack of Rochester, NY-based Excellus unique is that it took 20 months to discover. Eight large-scale hacks exposed more than 115 million records over the past two years, but none of the other breaches took over a year to discover.
Excellus has not come forth with any information explaining why the intrusion took so long to discover. At least 12 lawsuits have been filed against Excellus and its parent company, Lifetime HealthCare, and legislation is being drafted in the New York state legislature to address the security of sensitive personal information.