Company to pay $2.7M after Pennsylvanians COVID-19 contract tracing data leaked

(WHTM) – Insight Global LLC, which was hired by the Pennsylvania Department of Health to provide staffing for COVID-19 contact tracing, has agreed to pay $2.7 million for allegedly failing to provide adequate cyber security for thousands of resident’s contract tracing data.

According to the United States Department of Justice, Insight Global allegedly failed to protect personal health information for contract tracing subjects during the pandemic. As a result, some resident’s health information and/or personally identifiable information was transmitted in unencrypted emails.

insight_global_settlement_agreementDownload

Staff members also shared passwords and information was transmitted on Google files that were not password protected, according to the Justice Department.

From November 2020 through January 2021, the Justice Department alleged Insight Global managers received complaints from Insight Global staff that information was potentially insecure and accessible to the public. The issue was not addressed until April 2021.

In Cumberland County, a mother said her son’s information became public during the pandemic. He was one of about 70,000 residents affected.

“The resolution announced today reflects our continuing commitment to ensure that government contractors fulfill their cybersecurity obligations,” said Principal Deputy Assistant Attorney General Brian M. Boynton, head of the Justice Department’s Civil Division. “Failure to do so can compromise sensitive information of individuals and the government. The Justice Department will hold accountable those contractors who knowingly fail to satisfy cybersecurity requirements.”

Global Insight cooperated with the investigation and released the following statement

Insight Global took remedial action upon learning of the initial situation years ago, long before the Department of Justice opened its investigation.  While we believe that remediation was thorough and appropriate independent of the DOJ inquiry, we cooperated with their investigation, and we are pleased to have resolved this matter.

As one of the largest IT staffing companies in the United States, we certainly recognize how important data security is to our clients and their stakeholders, and we continue to make it a top priority. Since 2020, Insight Global has continued to strengthen its information security posture by reinforcing its compliance, data privacy, and risk functions, increasing its vendor due diligence, and implementing a host of additional controls and enhanced training programs.

Insight Global

“We will continue to work tirelessly here in the Middle District of Pennsylvania to make sure that those who do business with the government fulfill their commitments,” said U.S. Attorney Gerard M. Karam for the Middle District of Pennsylvania. “Increasingly, cybersecurity is a critical part of most, if not all, federally funded contracts. We are thankful for the support of HHS-OIG and their assistance in investigating this case.”

For the latest news, weather, sports, and streaming video, head to ABC27.