OPM Hack Affects 21.5M, Includes Individuals’ Health Info

July 13, 2015
Last week, the U.S. Office of Personnel Management (OPM) announced that 21.5 million individuals’ personal information was compromised during an attack of the agency's security clearance database—an incident that includes individuals’ health history and is related to a previous cyber attack on the agency.

Last week, the U.S. Office of Personnel Management (OPM) announced that 21.5 million individuals’ personal information was compromised during an attack of the agency's security clearance database—an incident that includes individuals’ health history and is related to a previous cyber attack on the agency.

In early June, OPM, an independent agency of the U.S. government that manages the civil service of the federal government, acknowledged a major breach had occurred, affecting background investigation records for current and former federal employees. The suspected China-based hackers breached OPM computers, stealing records of as many as four million current and former federal employees in one of the largest breaches of government personnel data. At the time, OPM only disclosed that the personnel records of 4.2 million current and former federal employees had been compromised.

OPM says this new incident is separate, but related to the previous one. Following the conclusion of the forensics investigation on the first incident, OPM determined that the types of information in those stolen records included identification details such as Social Security Numbers; residency and educational history; employment history; information about immediate family and other personal and business acquaintances; health, criminal and financial history; and other details. Some records also include findings from interviews conducted by background investigators and fingerprints.  Usernames and passwords that background investigation applicants used to fill out their background investigation forms were also stolen. The affected database contains copies of Standard Form 86, a questionnaire filled out by applicants for national security positions. The forms can include health data.

Now, OPM has concluded that sensitive information of 21.5 million individuals was stolen from the background investigation databases. With the 4.2 million people affected by the first breach, and 21.5 million included in an OPM repository of security clearance files, about 3.6 million of those affected were in both systems, an overlap that accounts for the 22.1 million in total, according to a Washington Post report.  

If an individual underwent a background investigation through OPM in 2000 or afterwards, it is highly likely that the individual is impacted by this cyber breach, the agency said. If an individual underwent a background investigation prior to 2000, that individual still may be impacted, but it is less likely.

Sponsored Recommendations

Harnessing the True Power of Cultural, Clinical and Operational Data

Optimize healthcare performance by combining clinical, operational, and cultural insights. A deeper understanding of team factors improves care and resource management.

How Digital Co-Pilots for patients help navigate care journeys to lower costs, increase profits, and improve patient outcomes

Discover how digital care journey platforms act as 'co-pilots' for patients, improving outcomes and reducing costs, while boosting profitability and patient satisfaction in this...

5 Strategies to Enhance Population Health with the ACG System

Explore five key ACG System features designed to amplify your population health program. Learn how to apply insights for targeted, effective care, improve overall health outcomes...

A 4-step plan for denial prevention

Denial prevention is a top priority in today’s revenue cycle. It’s also one area where most organizations fall behind. The good news? The technology and tactics to prevent denials...