DisclosureLens
MalwareHealthcareHealthcareRansomwareData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)PHIHealth (basic)Identity (basic)LowContained

ANTHEM INSURANCE COMPANIES, INC.

bd_e41b90ca71bec287 · schema v1 · pii pii-v1

Severity

Low

Discovered

May 1, 2021

Filed

Oct 15, 2021

To disclose

24 weeks

Affected

Not disclosed

Linked

2 filings

Confidence

65%
Full breach record for ANTHEM INSURANCE COMPANIES, INC.6 incidents on file

PracticeMax, a vendor for Anthem's VillageHealth program, experienced a ransomware attack between April 17 and May 5, 2021. Unauthorized access to a server containing Protected Health Information (PHI) was discovered on May 1, 2021. Affected data includes names, dates of birth, addresses, phone numbers, Anthem member IDs, and clinical kidney care data. PracticeMax engaged forensic investigators, rebuilt systems, enhanced firewalls, and offered 24 months of credit monitoring via Epiq.

Incident timeline

undetected · 14 days
discovery → filing · 24 weeks / 167 days

Apr 17, 2021

Begins

May 1, 2021

Discovered

Oct 15, 2021

Filed

vs. sector median

+11 wks slower

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings

View merged incident ↗
California State AGOct 15 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.