Anthem Inc.
bd_0bbff98139b67cc0 · schema v1 · pii pii-v1
Full breach record for Anthem Inc. →Anthem Inc., a health plan based in Indiana, reported to HHS OCR on 2015-02-13 (breach report filed 2015-03-13) that cyber-attackers exfiltrated ePHI for approximately 78.8 million individuals between 2014-12-02 and 2015-01-27, discovered on 2015-01-29. Initial access was via spear phishing of an Anthem subsidiary employee, leading to an advanced persistent threat intrusion. Stolen data included names, SSNs, medical identification numbers, addresses, dates of birth, email addresses, and employment information. Anthem agreed to a $16 million settlement and corrective action plan with HHS OCR to resolve potential HIPAA Privacy and Security Rule violations, including failures in enterprise-wide risk analysis, system activity review, incident response, and minimum access controls dating back to 2014-02-18.
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_8f37e1c095a846daCalifornia State AGfiled 2015-02-13Verified
- bd_76cd1b5530ae9e56Hawaii State AGfiled 2015-02-15(2d gap)Verified
- bd_c3e9d7c5bbd8b73bCalifornia State AGfiled 2015-02-10(3d gap)Verified
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Feb 13, 2015
- Raw hash
- d1f04886fff43b36ebe6fbce587ca52153f9c2f1f4b942cadc97065846e88126
Source filing
Reporting entity
- Name
- Anthem Inc.norm: anthem
- Domain
- anthem.com
Victim entity
- Name
- Anthem Inc.norm: anthem
- Domain
- anthem.com
- Industry
- Health Plan
- Industry
- Healthcaresource default
Incident
- Discovered
- Jan 29, 2015
- Materiality determined
- —
- Notification sent
- Mar 13, 2015
- Affected individuals
- 78,800,000
- Data types
- PHIPIIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICEMPLOYMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.001 Spearphishing AttachmentT1071 Application Layer ProtocolT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalEspionage
- Regulator citations
- HHS OCR breach report filed 2015-03-13HHS OCR Resolution Agreement and $16M settlementCorrective Action Plan
Compliance
- Time to disclose
- 15 days(15 days from discovery to filing)
- Compliance flags
- HIPAA 60-day OK · 43dHHS notified · 43d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Jan 29, 2015→ Notified: Mar 13, 201543d 60 days HIPAA 60-day OK HIPAA Discovered: Jan 29, 2015→ Notified: Mar 13, 201543d regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.