Star Health data leak: What recourse do policyholders have?

On 25 September, a cyber attacker using the alias ‘xenZen’ leaked a massive database through automated chatbots on Telegram. About 7.24 terabytes of data affecting 31 million customers has been compromised.

Aprajita Sharma
Published11 Oct 2024, 03:53 PM IST
Experts advise them to be vigilant about every call and message they receive to avoid further trouble. (Image: Pixabay)
Experts advise them to be vigilant about every call and message they receive to avoid further trouble. (Image: Pixabay)

Just as Star Health policyholders were grappling with the company's growing reputation for rejecting genuine claims, a new issue has surfaced, adding to their frustration.

The company suffered a severe hacking episode last month in which a hacker using the alias “xenZen” created a website and Telegram chatbots to leak its policyholders' sensitive personal data from names, phone numbers, email IDs, addresses to financial and health information. 

The hacker said Star Health's chief information security officer Amarjeet Khanuja sold the data to him and he made it public only when Khanuja reportedly sought more money than previously decided.

Star Health said Khanuja has been co-operating in the investigation and no wrongdoing by him had been found so far. 

About 7.24 terabytes of data affecting 31 million customers has been compromised.

"A thorough and rigorous forensic investigation, led by independent cybersecurity experts is underway, and we are working closely with government and regulatory authorities at every stage of this investigation, including by duly reporting the incident to the insurance and cybersecurity regulatory authorities apart from filing a criminal complaint," Star Health said in a media statement.

Also Read: Star Health data breach: Scope for mammoth scams amid few legal remedies?

CloudSEK, a Bengaluru-based data security firm, said the involvement of the CISO and other executives seems fabricated. According to CloudSEK, the threat actor shared two simultaneous chats—on the left, a TOX messaging platform known for anonymity, and on the right, emails allegedly from official Star Health accounts.

However, CloudSEK pointed out that this could easily be faked using a simple 'inspect element' trick to alter HTML, making the emails seem like they came from legitimate sources.

"Based on the available information, we can ascertain with high confidence that the threat actor has data that originates from Star Health Insurance. However, the involvement of the CISO and other executives seems highly unlikely and fabricated, to say the least," it added.

However, the very fact that the data breach has happened raises questions on Star Health's data security protocols.

What should policyholders do?

Star Health has assured its customers and partners that it has implemented robust security measures. The company has also sought legal action, with the Madras High Court ordering third parties to restrict access to the leaked information.

"We want to emphasize that any unauthorised acquisition, possession, or dissemination of customer data is illegal. We urge all platforms, hosting companies, social media channels and users to take swift and decisive action to halt such activities and comply with the orders of the High Court," the company said.

As for the leaked information, there's little a policyholder can do. Experts advise them to be vigilant about every call and message they receive to avoid further trouble. Beware of spam calls, unauthorized transactions or suspicious account logins.

"Policyholders should immediately change passwords across all key accounts, particularly banking, e-commerce, and health applications, to mitigate the risk of further unauthorized access. Opting for stronger password in addition, enabling two-factor authentication wherever possible will provide an extra layer of protection," said Neha Anand, vice president and head of cyber at Prudent Insurance Brokers.

Policyholders can also take proactive steps to protect their financial accounts by placing credit freezes or fraud alerts, she added.

Can policyholders take legal action?

While legal recourse is an option, proving damages stemming directly from a data breach can be complex, said Anand.

“If policyholders notice any misuse of their data linked to the breach, they should not hesitate to escalate the issue to regulatory authorities. Staying vigilant, informed, and proactive is the best way to safeguard one’s interests in such scenarios.”

Also read: Star Health Insurance under cyberattack, says operations unaffected even after data leak

Is it time to switch your policy to a different insurer?

Many policyholders are pondering over it. The recent data breach has only added to their concerns. Frequent claims rejections stories circulating on the social media are worrisome too.

Reasons for claim rejections range from unnecessary hospitalisations to discrepancies in documentation. In fact, some hospitals in Ahmedabad have reportedly blacklisted Star Health due to the cumbersome claims settlement process, said Aditya Shah, a health insurance expert and a CFA chartholder.

For current Star policyholders, porting to another insurer should be carefully considered. Shah advises that younger policyholders or those with less strict terms and conditions might consider porting. However, for older individuals or those with pre-existing conditions, the underwriting process can be tricky. Shah emphasizes that if Star Health wants to retain its customers, it must seriously re-evaluate and improve its claims settlement experience.

Also read: Health Insurance: Top-up vs. super top-up—Which one is right for you?

One needs to be mindful that there is no guarantee that a new insurer won’t present its own set of challenges. 

“It’s essential to consider other critical factors such as claim settlement ratios, customer service experience, and policy benefits before opting for a change. The insurer must swiftly implement robust data protection measures and maintain transparent communication to restore customer confidence and remain a viable option for current policyholders,” said Anand.

“However, if the insurer’s response is perceived as inadequate, policyholders can explore other insurance providers which are known for better claim handling and stringent data security protocols.”

Insurance Regulatory and Development Authority of India, meanwhile, remains silent on the issue. 

“Irdai must step in to enforce stringent data protection standards and mandatory disclosure of breaches as per DPDP (Digital Personal Data Protection) Act,” said Anand. “Swift regulatory action is needed to hold companies accountable, protect policyholders’ interests, and restore trust in the insurance sector’s commitment to safeguarding sensitive information.”

Key Takeaways
  • Be vigilant about spam calls, unauthorized transactions, and suspicious logins.
  • Immediately change passwords for banking, e-commerce, and health apps.
  • Enable two-factor authentication for extra security.
  • Consider placing credit freezes or fraud alerts to protect financial accounts.
  • Report any data misuse to regulatory authorities promptly.
  • Carefully consider switching insurers; younger policyholders may port, but older ones or those with pre-existing conditions should evaluate carefully.

Catch all the Instant Personal Loan, Business Loan, Business News, Money news, Breaking News Events and Latest News Updates on Live Mint. Download The Mint News App to get Daily Market Updates.

MoreLess
First Published:11 Oct 2024, 03:53 PM IST
Business NewsMoneyPersonal FinanceStar Health data leak: What recourse do policyholders have?

Get Instant Loan up to ₹10 Lakh!

  • Employment Type

    Most Active Stocks

    Power Grid Corporation Of India share price

    338.70
    03:50 PM | 26 NOV 2024
    -4.15 (-1.21%)

    Adani Power share price

    437.75
    03:58 PM | 26 NOV 2024
    -9.1 (-2.04%)

    Bharat Electronics share price

    297.80
    03:54 PM | 26 NOV 2024
    5.35 (1.83%)

    GAIL India share price

    193.90
    03:54 PM | 26 NOV 2024
    -5.25 (-2.64%)
    More Active Stocks

    Market Snapshot

    • Top Gainers
    • Top Losers
    • 52 Week High

    Piramal Enterprises share price

    1,197.35
    03:47 PM | 26 NOV 2024
    89.55 (8.08%)

    Laurus Labs share price

    545.00
    03:29 PM | 26 NOV 2024
    12.85 (2.41%)

    Wipro share price

    589.05
    03:58 PM | 26 NOV 2024
    6.3 (1.08%)

    Federal Bank share price

    213.55
    03:51 PM | 26 NOV 2024
    0.55 (0.26%)
    More from 52 Week High

    Poly Medicure share price

    2,775.00
    03:29 PM | 26 NOV 2024
    -227.7 (-7.58%)

    Adani Green Energy share price

    899.40
    03:59 PM | 26 NOV 2024
    -68.25 (-7.05%)

    DCM Shriram share price

    1,160.00
    03:29 PM | 26 NOV 2024
    -67.3 (-5.48%)

    Fortis Healthcare share price

    664.60
    03:59 PM | 26 NOV 2024
    -36.15 (-5.16%)
    More from Top Losers

    Piramal Enterprises share price

    1,197.35
    03:47 PM | 26 NOV 2024
    89.55 (8.08%)

    Triveni Turbines share price

    824.30
    03:54 PM | 26 NOV 2024
    60.4 (7.91%)

    Capri Global Capital share price

    210.00
    03:29 PM | 26 NOV 2024
    15.35 (7.89%)

    Vodafone Idea share price

    7.53
    03:59 PM | 26 NOV 2024
    0.55 (7.88%)
    More from Top Gainers

    Recommended For You

      More Recommendations

      Gold Prices

      • 24K
      • 22K
      Bangalore
      78,555.00-1,090.00
      Chennai
      78,561.00-1,090.00
      Delhi
      78,713.00-1,090.00
      Kolkata
      78,565.00-1,090.00

      Fuel Price

      • Petrol
      • Diesel
      Bangalore
      102.92/L0.00
      Chennai
      100.90/L0.00
      Kolkata
      104.95/L0.00
      New Delhi
      94.77/L0.00

      Popular in Money

        HomeMarketsloanPremiumMint Shorts