Anthem Inc.
ent_019e0bb1b66359a6984aeeaa9a272c45
Disclosures
19
HHS OCR · State AG · HHS OCR enforcement · 7 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
78,800,000
nationwide · HHS OCR IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Anthem Inc.
- Normalized
- anthem— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 6488TBAH4M731R9C4545
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- anthem.com
Disclosure history (19)newest first
- INDIANAHHS OCRas victim2022-09-30
Anthem ACE reported to HHS on 2022-09-30 a Unauthorized Access/Disclosure affecting 13,406 individuals. Breached information located on Network Server. A business associate inadvertently posted PHI (names, addresses, DOB, SSN) on the Internet, which was then exfiltrated. The CE notified HHS, individuals, and media; the BA implemented safeguards and retrained staff.
- California State AGas victim2021-12-31
Anthem, Inc. notified the California Attorney General of a data security incident involving its vendor, OneDigital. Unauthorized access to OneDigital's system occurred between January 12 and January 21, 2021, and was discovered on November 24, 2021. Affected data may include names, addresses, dates of birth, SSNs, driver's license numbers, and protected health information (PHI) such as medical records and claims data. Anthem is offering one year of credit monitoring to affected individuals.
- INDIANAHHS OCRas victim2021-11-19
Anthem, Inc. reported to HHS on 2021-11-19 a Hacking/IT Incident affecting 6118 individuals. Breached information located on Network Server. The breach compromised PHI including names, addresses, DOB, and treatment info. The CE and BA implemented additional administrative and technical safeguards.
- California State AGas victim2021-10-28
Anthem, Inc. notified members of a physical break-in at a vendor's office (The Foundation for Medical Care of Tulare & Kings Counties, Inc) on August 3, 2021. An unknown intruder stole an external backup drive containing scanned paper claims and correspondence. Anthem learned of the incident on August 16, 2021. Affected data includes PHI such as names, healthcare IDs, addresses, dates of birth, and diagnosis codes. Anthem is offering one year of credit monitoring.
- INDIANAHHS OCRas victim2021-10-27
Anthem, Inc. reported to HHS on 2021-10-27 a Theft affecting 5505 individuals. Breached information located on Other Portable Electronic Device, Paper/Films. The covered entity (CE), Anthem, Inc., reported that an external back-up device and claims folder containing the protected health information (PHI) of 5,505 individuals were stolen from its business associate’s office. The PHI involved included names, addresses, dates of birth, Social Security numbers, and claims information. The CE notified HHS, affected individuals, and the media. In response to the breach, the BA implemented additional physical and technical safeguards to better protect sensitive data.
- Illinois State AGas victim2021-01-01
ANTHEM filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-537). The register records the breach as discovered on October 1, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Montana State AGas victim2020-02-21
Anthem reported that on December 11, 2019, an unauthorized actor exported data from an associate's email account via malware after a phishing incident. Data included names, healthcare eligibility, ID numbers, and SSNs. Anthem quarantined the system, removed malware, and offered one year of Experian IdentityWorks monitoring. The incident was discovered on January 23, 2020.
- Illinois State AGas victim2020-01-01
ANTHEM filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-074). The register records the breach as discovered on January 23, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- FEDERALHHS OCR enforcementas victim2018-10-15
Anthem, Inc. agreed to pay $16 million to HHS OCR to settle potential HIPAA Privacy and Security Rules violations resulting from cyberattacks that exposed the electronic protected health information of nearly 79 million people.
- Montana State AGas victim2018-06-12
Anthem, Inc. notified Montana residents of a data breach involving a physician reviewer, Spyros Panos, who impersonated another licensed physician to access orthopedic claim files. The incident, discovered April 12, 2018, compromised PHI and demographic data. Anthem is reviewing denials and offering one year of identity monitoring.
- INDIANAHHS OCRas victim2017-07-24
Anthem, Inc. (Health Plan, IN) reported to HHS on 2017-07-24 an Unauthorized Access/Disclosure affecting 18,580 individuals. LaunchPoint Ventures, LLC, a business associate, reported that an employee impermissibly emailed PHI — including names, dates of birth, Social Security numbers, health insurance and treatment information — to his personal email account for identity theft purposes. LaunchPoint offered identity theft protection services, sanctioned the employee, retrained staff, and implemented additional administrative safeguards. OCR obtained assurances of corrective action.
- INDIANAHHS OCRas victim2016-10-26
An Anthem, Inc. (IN) employee emailed PHI to himself, claiming it was for commission reconciliation purposes. The breach, affecting 3,525 individuals, was submitted to HHS on 2016-10-26. PHI was located in email. The employee resigned and attested to deleting all PHI from personal devices. Anthem retrained its Medicare sales workforce and updated commission statements to limit PHI. OCR obtained written assurances of corrective action implementation.
- Massachusetts State AGas victim2015-09-25
Anthem reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2015-09-25. 622 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2015-07-14
Anthem reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2015-07-14. 654,393 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2015-03-16
Anthem reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2015-03-16. 23 Massachusetts residents were affected. The report records the breach type as electronic.
- Hawaii State AGas victim2015-02-15
Anthem, Inc. notified Hawaii OCP of a cyber-attack where attackers used stolen database admin credentials to access member data (names, SSNs, DOB, addresses, employment info) between Dec 10, 2014 and Jan 27, 2015. Discovery was Jan 27, 2015. Mandiant engaged; no financial/medical data accessed. Resident count pending.
- INDIANAHHS OCRas victim2015-02-13
Anthem Inc., a health plan based in Indiana, reported to HHS OCR on 2015-02-13 (breach report filed 2015-03-13) that cyber-attackers exfiltrated ePHI for approximately 78.8 million individuals between 2014-12-02 and 2015-01-27, discovered on 2015-01-29. Initial access was via spear phishing of an Anthem subsidiary employee, leading to an advanced persistent threat intrusion. Stolen data included names, SSNs, medical identification numbers, addresses, dates of birth, email addresses, and employment information. Anthem agreed to a $16 million settlement and corrective action plan with HHS OCR to resolve potential HIPAA Privacy and Security Rule violations, including failures in enterprise-wide risk analysis, system activity review, incident response, and minimum access controls dating back to 2014-02-18.
- California State AGas victim2015-02-13
On January 29, 2015, Anthem, Inc. discovered a sophisticated cyber attack that gained unauthorized access to its IT system. The attack likely began in early December 2014. Personal information including names, dates of birth, Social Security numbers, health care ID numbers, addresses, email addresses, and employment information was accessed. Anthem contacted the FBI and retained Mandiant for investigation. Identity protection services were provided to impacted individuals.
- INDIANAHHS OCRas victim2013-08-13
Anthem BCBS of GA reported to HHS OCR on 2013-08-13 a Theft (impermissible disclosure) affecting 5,497 individuals. A CE sales representative used an incorrect group number from an erroneous membership/data file, causing inadvertent disclosure of PHI including demographic information to a business associate. The BA subsequently certified destruction of the PHI. OCR confirmed the CE implemented corrective action including enhanced quality control procedures and counseling of the involved representative.
Supply-chain cascadesreviewed and confirmed
- Anthem Inc.’s filing is one of at least 3 in the OneDigital Investment Advisors LLC supply-chain incident (2021).