Anthem, one of the largest US health insurers, disclosed that attackers had breached a database holding personal information on current and former members and employees. The number of people affected was later put at 78.8 million, making it one of the largest healthcare breaches on record.
What happened
- Exposed data included names, dates of birth, member ID numbers, Social Security numbers, addresses, and employment information.
- Anthem said it had no evidence that medical or payment card information was taken.
- In 2019, US prosecutors charged a Chinese national and an accomplice, describing them as part of a sophisticated hacking group.
- Anthem later agreed a record 115 million US dollar class action settlement, paid 16 million US dollars to US health regulators in 2018, and settled with state attorneys general in 2020.
Why it mattered
The breach showed that health insurers hold highly valuable identity data and led to record penalties in the US healthcare sector. It also raised concerns about unencrypted sensitive data in large databases.
Lessons for organisations
Organisations holding sensitive personal data should encrypt it at rest, restrict and monitor database access, and protect administrator accounts against phishing with multi-factor authentication. Data minimisation reduces what can be stolen.
Sources: FierceHealthcare, BankInfoSecurity
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.