Premera Blue Cross publicly disclosed on March 17, 2015 a cyber intrusion that compromised the electronic protected health information of 10,466,692 individuals, with attackers having dwelled undetected in its network for roughly nine months. Advanced persistent threat actors gained an initial foothold via a phishing email in May 2014 and were not identified until Premera's January 29, 2015 discovery of the compromise. Exposed data included names, dates of birth, Social Security numbers, member identification numbers, mailing and email addresses, telephone numbers, bank account information, and claims information, including clinical data. On September 25, 2020 Premera paid $6.85 million to the HHS Office for Civil Rights to resolve potential HIPAA Privacy and Security Rule violations, characterized by OCR as the second-largest HIPAA enforcement payment in its history; the accompanying corrective action plan required a comprehensive risk analysis, remediation of access-control and encryption gaps, workforce training, and two years of OCR monitoring. Premera also settled consolidated multidistrict consumer class actions for $74 million in 2019 and reached a $10 million settlement with a 30-state attorney general coalition the same year.
Blog
Insights on AI security and development
Learn how to protect your code, understand AI risks, and build secure workflows with expert insights.

