Don’t do SECURITY. Do business SECURELY.

Anthem cyber attack exposes records of nearly 79 million people

US health insurer Anthem disclosed a cyber attack exposing names, dates of birth, and Social Security numbers of nearly 79 million people.

Anthem, one of the largest US health insurers, disclosed that attackers had breached a database holding personal information on current and former members and employees. The number of people affected was later put at 78.8 million, making it one of the largest healthcare breaches on record.

What happened

  • Exposed data included names, dates of birth, member ID numbers, Social Security numbers, addresses, and employment information.
  • Anthem said it had no evidence that medical or payment card information was taken.
  • In 2019, US prosecutors charged a Chinese national and an accomplice, describing them as part of a sophisticated hacking group.
  • Anthem later agreed a record 115 million US dollar class action settlement, paid 16 million US dollars to US health regulators in 2018, and settled with state attorneys general in 2020.

Why it mattered

The breach showed that health insurers hold highly valuable identity data and led to record penalties in the US healthcare sector. It also raised concerns about unencrypted sensitive data in large databases.

Lessons for organisations

Organisations holding sensitive personal data should encrypt it at rest, restrict and monitor database access, and protect administrator accounts against phishing with multi-factor authentication. Data minimisation reduces what can be stolen.

Sources: FierceHealthcare, BankInfoSecurity

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with a link to our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights