Premera Blue Cross
bd_13935cd688d3ab10 · schema v1 · pii pii-v1
Full breach record for Premera Blue Cross →7 incidents on filePremera Blue Cross notified Hawaii regulators of a cyberattack where unauthorized access to IT systems occurred on May 5, 2014, and was discovered on January 29, 2015. Attackers may have accessed names, SSNs, DOBs, bank accounts, and clinical data. Premera engaged Mandiant for investigation, notified the FBI, and began notifying affected individuals on March 17, 2015, offering two years of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
May 5, 2014
Begins
Jan 29, 2015
Discovered
Mar 24, 2015
Filed
vs. sector median
5 wks faster
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- New Hampshire State AGbd_69d72a8fe88cec392015-03-27 · +3dVerified
- South Carolina State AGbd_9ec8af423fb684d52015-03-19 · +5dVerified
- Massachusetts State AGbd_de2d028bf0408dea2015-03-18 · +6dVerified
- HHS OCRbd_9a804b5de84dfb072015-03-17 · +7dVerified
Show 5 more filings ↓Show fewer ↑up to 2012d gap
- California State AGbd_e8e76c27f5c889f62015-03-17 · +7dCandidate
- New Hampshire State AGbd_f653fc0c8376c8532015-03-17 · +7dVerified
- New Hampshire State AGbd_bc5a1df54eb15c132015-04-02 · +9dVerified
- New Hampshire State AGbd_f240484574e352ba2015-05-04 · +41dVerified
- HHS OCR enforcementbd_d2050db6681c56222020-09-25 · +2012dVerified by operator
Filing propagation · 10 filings · 6 states
View merged incident ↗Pattern: first filing Mar 17 (WA), last Sep 25 — a 2019-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.