Anthem Inc. disclosed on February 4, 2015 a criminal cyberattack initially affecting 37.5 million records, later revised by February 24, 2015 to 78.8 million people, making it the largest U.S. health-data breach at the time. State insurance commissioners later attributed the intrusion to a foreign government-directed actor that first gained access on February 18, 2014 and exfiltrated data for weeks before discovery. Compromised information included names, dates of birth, medical IDs, Social Security numbers, street and email addresses, and employment data, though Anthem said medical records and financial data were not taken. In 2017 Anthem settled approximately 100 consolidated class actions for $115 million, then the largest data-breach class settlement on record. The Department of Health and Human Services Office for Civil Rights followed with a $16 million HIPAA resolution agreement in October 2018, then the largest HIPAA settlement ever, and an October 2020 multistate attorneys general settlement added another $48.2 million, bringing aggregate payouts to roughly $179.2 million. Corrective-action obligations required Anthem to conduct risk assessments, implement cybersecurity improvements and submit to multi-year HHS oversight, setting a baseline for HIPAA enforcement against insurers.
Blog
Insights on AI security and development
Learn how to protect your code, understand AI risks, and build secure workflows with expert insights.

