Aetna, a U.S. health insurance company, has been fined $1 million for three data breaches that occurred over a six-month period in 2017. Aetna agreed to the fine and to adopt a remediation plan to resolve potential violations of the privacy and security rules of the Health Insurance Portability and Accountability Act (HIPAA). The payment will be deposited with the Office of Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS).
On April 27, 2017, the U.S. health insurance company discovered that two online services it used to display plan-related documents to health plan members had allowed documents to be accessed without credentials . As a result of this breach, sensitive and confidential data of over 5,000 individuals was exposed. The protected health information (PHI) exposed in the incident included information payment, codes service.

Aetna suffered a second data breach on July 28, 2017, when benefit notices sent to members in window envelopes displayed the words “HIV medications” next to the member’s name and address. A breach report filed with OCR in August said that about 12,000 people were affected by that disclosure.
The third breach of 2017 that hit Aetna took place on September 25, when a research study sent to members showed the name and logo of the atrial fibrillation research study in which they participated. Aetna reported in November 2017 that 1,600 people were affected by this breach.

The OCR's investigation into data breaches found that, aside from the unwanted disclosures, Aetna failed to conduct periodic technical and non-technical assessments of the operational changes that affect the security of PHI.
James McQuiggan, an attorney in the security awareness department at KnowBe4, told Infosecurity Magazine that organizations need to have a robust security awareness training program in place to help employees make smarter security decisions to protect an organization from various forms of attacks .
