Balita.org: Your Premier Source for Comprehensive Philippines News and Insights! We bring you the latest news, stories, and updates on a wide range of topics, including politics, culture, economy, and more. Stay tuned to know everything you wish about your favorite stars 24/7.

Contacts

  • Owner: SNOWLAND s.r.o.
  • Registration certificate 06691200
  • 16200, Na okraji 381/41, Veleslavín, 162 00 Praha 6
  • Czech Republic

PhilHealth negligence eyed in data breach

MANILA, Philippines — The National Privacy Commission (NPC) is investigating if there was negligence in the handling of personal information and security committed by Philippine Health Insurance Corp. (PhilHealth) regarding a recent ransomware attack.

Apart from negligence, the privacy commission is also looking if there is concealment and possible imposition of administrative fines, pending the outcome of its investigation, NPC Public Information and Assistance Division chief Roren Chin said in a Viber message to reporters.

According to her, the administrative fines could reach as much as P5 million.

Chin explained that NPC administrative fines are monetary penalties imposed by the NPC for non-criminal violations of data privacy regulations, and are distinct from the criminal penalties specified in the Data Privacy Act.

“We have identified that certain documents from the video released by Medusa contained personal information, including IDs and photographs,” Chin said.

“Currently, we are actively verifying whether these individuals have any affiliation with PhilHealth, either as employees or members,” she added.

Last week, the NPC said it was notified by PhilHealth regarding the alleged ransomware attack.

“We have issued a Notice to Explain to PhilHealth, seeking comprehensive information regarding the nature and extent of the data breach,” the NPC said last week.

Apart from the notice to explain, the NPC also issued PhilHealth a notice to appear at a hearing scheduled last Sept. 26. It added that this was followed by a Notice of Onsite Investigation on Sept. 28.

“These actions have been initiated to evaluate the impact of the alleged data breach and to assess the mitigation efforts undertaken by PhilHealth, with a primary focus on protecting the interests of the affected beneficiaries and contributors,” the NPC said earlier.

In a statement on Tuesday, PhilHealth said it has actively been reaching out to the public and employees whose information may have been compromised.

The agency also emphasized that the ransomware attack did not affect its servers containing members’ private information.

“PhilHealth’s membership database, claims, contribution and

Read more on philstar.com
DMCA