Let us take care of you

Notice of Data and Privacy Event

Notice of Data Breach

Pacific Specialty Insurance Company recently discovered an incident that may affect the security of personal information of certain current and former customers.  We take this incident very seriously and the confidentiality, privacy, and security of our information is one of our highest priorities.

What Happened?

On June 14, 2019 Pacific Specialty Insurance Company became aware of suspicious activity in employee email accounts.  We immediately began an investigation to determine what happened and what information may have been affected.  With the assistance of third-party forensic investigators, we determined that certain employee email accounts were subject to unauthorized access between March 20, 2019 and March 30, 2019.  These email accounts were then reviewed to determine whether they contained any personal identifying information. 

What Information Was Involved?

The types of information contained within the potentially impacted emails varied by individual but include:  an individual’s name, Social Security number, driver’s license and/or government issued identification, financial information, payment card information, medical information, and health insurance information.

Pacific Specialty Insurance Company is not aware of any reported attempted or actual misuse of any personal information as a result of this event.

What Is Pacific Specialty Insurance Company Insurance Doing in Response to this Incident? 

Pacific Specialty Insurance Company is committed to, and takes very seriously, its responsibility to protect all data entrusted to us.  We are continuously taking steps to enhance data security protections.  As part of our incident response, we changed the log-in credentials for all employee email accounts to prevent further unauthorized access.  Since then, we have continued ongoing efforts to enhance security controls, such as enabling multifactor authentication, and implemented additional controls to help protect employee email accounts from unauthorized access.  In an abundance of caution, we are offering 12 months of complimentary credit monitoring to potentially affected individuals so that they may take further steps to best protect their personal information, should they feel it is appropriate to do so.  We are also notifying any required federal and state regulators.

What Should I Do in Response to this Incident? 

Pacific Specialty Insurance Company encourages you to remain vigilant against incidents of identity theft and fraud. You should review your account statements or your loved ones’ account statements for suspicious activity.  If you see any unauthorized charges, promptly contact the bank or credit card company.  We also recommend reviewing your credit report for inquiries from companies that you have not contacted, accounts you did not open and debts on your accounts that you cannot explain.

What Should I Do in Response to this Incident? 

Pacific Specialty Insurance Company encourages you to remain vigilant against incidents of identity theft and fraud. You should review your account statements or your loved ones’ account statements for suspicious activity.  If you see any unauthorized charges, promptly contact the bank or credit card company.  We also recommend reviewing your credit report for inquiries from companies that you have not contacted, accounts you did not open and debts on your accounts that you cannot explain.

Experian

TransUnion

Equifax

PO Box 9554

P.O. Box 2000

PO Box 105788

Allen, TX 75013

Woodlyn, PA 19094

Atlanta, GA 30348-5788

1-888-397-3742

1-800-909-8872

1-800-685-1111

www.experian.com/freeze/center.html

www.transunion.com/credit-freeze

www.equifax.com/personal/credit-report-services

In order to request a security freeze, you will need to provide the following information:

 

  1. Your full name (including middle initial as well as Jr., Sr., II, III, etc.);
  2. Social Security number;
  3. Date of birth;
    If you have moved in the past five (5) years, provide the addresses where you have lived over the prior five years;
  4. Proof of current address, such as a current utility bill or telephone bill;
  5. A legible photocopy of a government-issued identification card (state driver’s license or ID card, military identification, etc.);
  6. If you are a victim of identity theft, include a copy of either the police report, investigative report, or complaint to a law enforcement agency concerning identity theft.

 

As an alternative to a security freeze, you have the right to place an initial or extended “fraud alert” on your file at no cost.  An initial fraud alert is a 1-year alert that is placed on a consumer’s credit file.  Upon seeing a fraud alert display on a consumer’s credit file, a business is required to take steps to verify the consumer’s identity before extending new credit.  If you are a victim of identity theft, you are entitled to an extended fraud alert, which is a fraud alert lasting seven years.  Should you wish to place a fraud alert, please contact any one of the agencies listed below:

Experian

TransUnion

Equifax

PO Box 9554

P.O. Box 2000

PO Box 105788

Allen, TX 75013

Woodlyn, PA 19094

Atlanta, GA 30348-5788

1-888-397-3742

1-800-909-8872

1-800-685-1111

www.experian.com/freeze/center.html

www.transunion.com/credit-freeze

www.equifax.com/personal/credit-report-services

Additional Information 

Instances of known or suspected identity theft should be reported to law enforcement and the Federal Trade Commission.  The Federal Trade Commission can be reached at: 600 Pennsylvania Avenue NW, Washington, DC 20580; www.identitytheft.gov; 1-877-ID-THEFT (1-877-438-4338); and TTY: 1-866-653-4261.  The Federal Trade Commission encourages those who discover that their information has been misused to file a complaint with them.

Questions regarding the incident should be directed to 833-991-1528 Monday through Friday 8:00 AM to 8:00 PM (Central).

Privacy Notice at Collection for CA employees

Last updated: June 27, 2023

  1. About this Notice. This privacy notice sets out how The McGraw Group of Affiliated Companies collects and uses personal information about you in compliance with our obligations under the California Consumer Privacy Act of 2018 (CCPA), as amended by the California Privacy Rights Act of 2020 (CPRA). This Notice supplements all other privacy policies we have in place.

We take the privacy of our employees and applicants very seriously. Please read this notice carefully as it contains important information on the personal information that we collect, why we collect it, how long we keep it, and that it is not sold to third parties.

  1. Key Terms. The following key terms are used in this notice:
  • We, us, our. The McGraw Group of Affiliated Companies.
  • Personal information. Any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with a particular individual.
  • Sensitive personal information. Personal information revealing an individual’s social security number, driver’s license and passport numbers, account numbers and credentials, precise geolocation, racial or ethnic origin, religious beliefs, or union membership, personal information concerning a consumer’s health, sex life, or sexual orientation, contents of a consumer’s mail, email and text messages where the business is not the intended recipient, genetic data, and biometric information.
  • Biometric Information. An individual’s physiological, biological, or behavioral characteristics, including information pertaining to an individual’s deoxyribonucleic acid (DNA), that is used or is intended to be used singly or in combination with each other or with other identifying data, to establish individual identity. Biometric information includes, but is not limited to, imagery of the iris, retina, fingerprint, face, hand, palm, vein patterns, and voice recordings, from which an identifier template, such as a faceprint, a minutiae template, or a voiceprint, can be extracted, and keystroke patterns or rhythms, gait patterns or rhythms, and sleep, health, or exercise data that contain identifying information.

Other terms used but not defined will have the meaning set forth in the CCPA, as amended by the CPRA, Cal. Civ. Code §§ 1798.100—1798.199.100, and accompanying regulations set forth under Cal. Code Regs. tit. 11, § 7000 et seq.

  1. Personal Information We Collect About You. We may collect and use the following categories of personal information about you:

Categories of Personal Information Collected

  • Identifiers: Name, alias, postal address, email address, phone number, account name, social security number, driver’s license number, passport number, or other similar identifiers.
  • Employment-related information such as your job title, salary, benefits information, emergency contact information, references, qualifications, skills and experience.
  • Personal information as defined in Customer Records law: Name, signature, social security number, physical characteristics or description, address, telephone number, passport number, driver’s license or state identification card number, education, professional license number employment history, bank account number, other financial information, medical information, and/or health insurance information.
  • Characteristics of protected classifications under California or federal law such as race, age, sex, familial status, and disability.
  • Audio, electronic, visual, or similar information such as photographs and call recordings
  • Background check information such as your criminal and credit history
  • Inferences are not drawn from any of the information identified above to create a profile reflecting your preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.
  1. How and Why We Use Your Personal Information. We use your personal information for the following purposes:

Purposes for Collecting and Using Your Personal Information

Managing Human Resource Functions:

  • Recruiting, hiring, and onboarding
  • Performing background checks
  • Implementing diversity and inclusion initiatives
  • Training and career development
  • Assessing performance
  • Determining promotions, transfers, salary, awards, and bonuses
  • Managing disciplinary matters
  • Managing payroll and business expenses
  • Administering leave requests
  • Employee communications
  • Administration of benefits
  • Promoting employee health and safety

Conducting business operations:

  • Budgeting
  • Recordkeeping and reporting requirements
  • Managing infrastructure and company assets
  • Strategic planning
  • Maintaining security and risk management
  • Emergency response and business continuity
  • Conducting audits
  • Pursuing or defending legal or administrative claims

Monitoring:

  • Compliance
  • Use of company resources
  • Any other monitoring activities permitted by applicable laws

Compliance with:

  • Legal and regulatory obligations
  • Court or other government directives
  • Internal policies and procedures

Investigating:

  • Reports of wrongdoing
  • Policy violations
  • Internal complaints
  1. Whether Personal Information Will Be Sold or Shared. We do not sell or share the personal information of employees.
  2. How Long Your Personal Information Will Be Kept. We will keep your personal information for as long as is necessary while you are employed by us. Thereafter, we will keep your personal information:
  • To respond to any questions, complaints or claims made by you or on your behalf or;
  • To keep records required by law. In California, this is currently and generally a minimum of four (4) years.

We will not retain your personal information for longer than necessary for the purposes set out in this notice. Different retention periods apply for different types of personal information.

When it is no longer necessary to retain your personal information, we will delete or anonymize it.

  1. If you have any questions or concerns about this notice or the information we collect about you, please contact send an email to privacy@pacificspecialty.com.