HackingSupply Chain (3P Vendor)Customer Data InvolvedPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
ANTHEM INSURANCE COMPANIES, INC.
bd_9e9aa91910c31ab6 · schema v1 · pii pii-v1
Full breach record for ANTHEM INSURANCE COMPANIES, INC. →Anthem, Inc. notified the California Attorney General of a data security incident involving its vendor, OneDigital. Unauthorized access to OneDigital's system occurred between January 12 and January 21, 2021, and was discovered on November 24, 2021. Affected data may include names, addresses, dates of birth, SSNs, driver's license numbers, and protected health information (PHI) such as medical records and claims data. Anthem is offering one year of credit monitoring to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-549043
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 31, 2021
- Raw hash
- 1b368a8bf6a5aa1327951bbb5f4e32e6805563dd4524f1bd9f43588d81bc3094
Reporting entity
- Name
- ANTHEM INSURANCE COMPANIES, INC.norm: anthem insurance companies
- Domain
- anthem.com
Victim entity
- Name
- ANTHEM INSURANCE COMPANIES, INC.norm: anthem insurance companies
- Domain
- anthem.com
Incident
- Discovered
- Nov 24, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- Threat actor
- External
- Third party
- via OneDigital
- Initial access
- supply_chain
Compliance
- Time to disclose
- 5 weeks(37 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.