Anthem Inc.
bd_a56022fe9b9d5b17 · schema v1 · pii pii-v1
Full breach record for Anthem Inc. →Anthem, Inc. reported to HHS on 2021-10-27 a Theft affecting 5505 individuals. Breached information located on Other Portable Electronic Device, Paper/Films. The covered entity (CE), Anthem, Inc., reported that an external back-up device and claims folder containing the protected health information (PHI) of 5,505 individuals were stolen from its business associate’s office. The PHI involved included names, addresses, dates of birth, Social Security numbers, and claims information. The CE notified HHS, affected individuals, and the media. In response to the breach, the BA implemented additional physical and technical safeguards to better protect sensitive data.
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_9b9bf2a33a0aa022California State AGfiled 2021-10-28(1d gap)Verified
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Oct 27, 2021
- Raw hash
- 22ea7d78bd1ad640163a8083983daf62891cfbdf5e694685ab044ef06e62ad5e
Source filing
Reporting entity
- Name
- Flag & Anthemnorm: flag anthem
- Domain
- flagandanthem.com
- Industry
- Health Care Services
Victim entity
- Name
- Anthem Inc.norm: anthem
- Domain
- anthem.com
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 5,505
- Data types
- PHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- External
- Regulator citations
- The CE notified HHS
- Third party
- via Anthem, Inc.business associate
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.