McKee Says “HealthyRhode” Customers to Get to “RI Bridges” Via “UHIP” - Are You Confused?

GoLocalProv News Team

McKee Says “HealthyRhode” Customers to Get to “RI Bridges” Via “UHIP” - Are You Confused?

Governor Dan McKee. PHOTO: Richard McCaffrey for GoLocal
If you are confused by Governor Dan McKee’s announcement on Thursday about the latest state workaround for the hacked Rhode Island database, join the club.

McKee and members of his administration announced at a press conference that if you were one of the 650,000 impacted, then you may be getting an email at some point in the future.

Further, the new workaround has been built by the state’s vendor, Deloitte, which is the same Deloitte that is being sued in federal court in multiple class action lawsuits for their failure to protect Rhode Islander's most sensitive data.

GET THE LATEST BREAKING NEWS HERE -- SIGN UP FOR GOLOCAL FREE DAILY EBLAST

McKee’s office said in the announcement, “This development comes after a successful relaunch of the system’s internally facing employee portal earlier this month. Previously, the State proactively took the RIBridges system offline due to security concerns associated with the recent data breach. After extensive testing and validation by Deloitte—the manager of RIBridges, the State, and the State’s third-party risk assessor, it has been determined that RIBridges is safe to use.”

GoLocal asked McKee’s office why Deloitte who the firm being blamed for the cyberattack, is working on the workaround.

McKee's office did not respond.

SEE THE HISTORY OF DELOITTE IN RI BELOW

It is believed that the personal data, including social security numbers, personal banking information, dates of birth, and additional personal information for 650,000 have been stolen by cyber attackers. Some of it has been found on the so-called "dark web."

 

Lawsuits Against Deloitte

Law firm Motley Rice wrote in its recent federal lawsuit against Deloitte, that the consulting company is to blame. 

“Defendant disregarded the rights of Plaintiff and Class Members by, among other things, intentionally, willfully, recklessly, or negligently failing to implement adequate and reasonable measures to protect its data systems against unauthorized intrusions; failing to take standard and reasonably available steps to prevent the Data Breach; and failing to provide Plaintiff and Class Members prompt and accurate notice of the Data Breach,” according to the lawsuit. 

Moreover, the lawsuit asserts the breach has the capacity to cause present and future harm. 

“With access to the Private Information obtained in the Data Breach, data thieves have already engaged in identity theft and fraud. Additionally, the data thieves can and will commit crimes in the future including, for example, opening new financial accounts in Class Members’  names, taking out loans in Class Members’ names, using Class Members’ information to obtain government benefits, filing fraudulent tax returns using Class Members’ information, obtaining driver’s licenses in Class Members’ names but with another person’s photograph, and giving false information to police during an arrest,” the lawsuit alleges. 

 

 

According to McKee's office, this is the new process:

The customer [those 650,000 that were hacked] e-mails will originate from the following address: [email protected]. Customers who do not receive an e-mail should not attempt to log in; if they do, they will be denied access.

What Customers Should Know

 

    •    At this time, customers with accounts can only log in after receiving an e-mail from [email protected]. During the phased relaunch, if a customer has not received an e-mail and attempts to log in early, they will not be able to log in. Customers should check their email periodically for updates about when they can access their accounts.

 

    •    The e-mail from [email protected] will not include any clickable links, as we want customers to be confident that this is not a phishing attempt or fraudulent message. Customers can go to healthyrhode.ri.gov to log in to their accounts. The email will have the state seal at the top and customers can scroll for Spanish and Portuguese translations. The state will not publish the e-mail online.

 

    •    Customers will log in with their username and current password and then be prompted to reset their password. After successfully resetting their password, they should be able to access their account. If a customer forgets their username or password, they should click on the “Forgot username/password” link for assistance. A customer will be locked out after three failed attempts to sign in and can only change their password once every 24 hours.

 

    •    During the initial relaunch process, existing or prospective customers who do not currently have a HealthyRhode account will not be able to create one. Account creation will be enabled soon. In the meantime, customers who need to manage existing benefits or apply for benefits can do so by contacting the Rhode Island Department of Human Services (DHS) or HealthSource RI (HSRI) directly. Likewise, the HealthyRhode Mobile app is not yet available.

 

    •    If customers have trouble logging in, resetting their password, or navigating their account, they should call the DHS or HSRI call center. Information about phone numbers and call center hours can be found at cyberalert.ri.gov.


History of Deloitte and UHIP in Rhode Island

Enjoy this post? Share it with others.