Pennsylvania part of $5.5 million settlement for Nationwide data - WFMJ.com News weather sports for Youngstown-Warren Ohio

Pennsylvania part of $5.5 million settlement for Nationwide data breach

Posted: Updated:
HARRISBURG, Pa. -

Pennsylvania and 32 other states have reached a settlement with Nationwide Mutual Insurance Company and a subsidiary for a data breach that resulted in the loss of personal information belonging to more than 1.2 million Americans, including 36,000 Pennsylvanians.

The data breach, caused by what Pennsylvania Attorney Josh Shapiro says was the companies’ alleged failure to apply a critical security patch, resulted in the loss of people's social security numbers, driver’s license numbers, credit information and other personal data.

The lost personal information was collected by Nationwide in order to provide insurance quotes to consumers applying for insurance.

As part of the settlement, Nationwide and its subsidiary, Allied Property & Casualty Insurance Company, agreed to pay $5.5 million to a group of 33 attorneys general to resolve the data breach investigation. Of that total, Pennsylvania will receive $248,830.

The settlement requires Nationwide to initiate a series of actions to update its security and ensure the timely application of patches and other updates to its security software:

Nationwide must hire a technology officer responsible for monitoring and managing software and application security updates.

Strengthen its procedures relating to the maintenance and storage of consumer data.

Conduct regular inventories of the patches and updates applied to its systems used to maintain consumers’ personal information.

Hire an outside, independent provider to perform an annual audit of its practices regarding the collection and maintenance of consumers’ personal information.

Many of the consumers whose data was lost as a result of the data breach never became insured by Nationwide. However, the company retained their data in order to more easily provide re-quotes at later times.

The settlement requires Nationwide to be more transparent about its data collection practices and compels it to disclose to consumers that it retains their information even if they do not become customers.

The Federal Trade Commission offers free credit reports here.

Powered by Frankly
All content © Copyright 2000 - 2017 WFMJ. All Rights Reserved. For more information on this site, please read our Privacy Policy and Terms