Anthem Inc.
ent_019e0bb1b66359a6984aeeaa9a272c45
Disclosures
14
Leak Site · HHS OCR · State AG · 6 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
78,800,000
as filed · HHS OCR FEDERAL
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- Anthem Inc.
- Normalized
- anthem— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 6488TBAH4M731R9C4545
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- anthem.com
Disclosure history (14)newest first
- GLOBALLeak Siteas victim2025-08-09
all data
- INDIANAHHS OCRas victim2021-11-19
Anthem, Inc. reported to HHS on 2021-11-19 a Hacking/IT Incident affecting 6118 individuals. Breached information located on Network Server. The breach compromised PHI including names, addresses, DOB, and treatment info. The CE and BA implemented additional administrative and technical safeguards.
- 🐻California State AGas victim2021-10-28
Anthem, Inc. reported a physical break-in at a third-party vendor's office on August 3, 2021. The vendor, The Foundation for Medical Care of Tulare & Kings Counties, Inc., had an external backup drive stolen containing scanned paper claims. The breach exposed PHI including names, addresses, dates of birth, and healthcare IDs. Anthem notified affected individuals on October 29, 2021, offering one year of credit monitoring.
- INDIANAHHS OCRas victim2021-10-27
Anthem, Inc. reported to HHS on 2021-10-27 a Theft affecting 5505 individuals. Breached information located on Other Portable Electronic Device, Paper/Films. The covered entity (CE), Anthem, Inc., reported that an external back-up device and claims folder containing the protected health information (PHI) of 5,505 individuals were stolen from its business associate’s office. The PHI involved included names, addresses, dates of birth, Social Security numbers, and claims information. The CE notified HHS, affected individuals, and the media. In response to the breach, the BA implemented additional physical and technical safeguards to better protect sensitive data.
- 🦬Montana State AGas victim2020-02-21
Anthem reported a data breach to the Montana Attorney General. The breach was reported on 2020-02-21. The breach occurred on 12/11/2019. 1 Montana residents were affected.
- 🦬Montana State AGas victim2018-06-12
Anthem, Inc. reported a data breach to the Montana Attorney General. The breach was reported on 2018-06-12. The breach occurred from 8/1/2013 to 4/10/2018. 2 Montana residents were affected.
- INDIANAHHS OCRas victim2017-07-24
Anthem, Inc. (Health Plan, IN) reported to HHS on 2017-07-24 an Unauthorized Access/Disclosure affecting 18,580 individuals. LaunchPoint Ventures, LLC, a business associate, reported that an employee impermissibly emailed PHI — including names, dates of birth, Social Security numbers, health insurance and treatment information — to his personal email account for identity theft purposes. LaunchPoint offered identity theft protection services, sanctioned the employee, retrained staff, and implemented additional administrative safeguards. OCR obtained assurances of corrective action.
- INDIANAHHS OCRas victim2016-10-26
An Anthem, Inc. (IN) employee emailed PHI to himself, claiming it was for commission reconciliation purposes. The breach, affecting 3,525 individuals, was submitted to HHS on 2016-10-26. PHI was located in email. The employee resigned and attested to deleting all PHI from personal devices. Anthem retrained its Medicare sales workforce and updated commission statements to limit PHI. OCR obtained written assurances of corrective action implementation.
- 🐻California State AGas victim2015-06-01
YP Holdings submitted a California SB-24 breach notification regarding a cyber attack on its healthcare provider, Anthem, Inc. The incident, discovered on January 5, 2015, involved unauthorized access to Anthem's IT systems starting in December 2014. Affected data included names, Social Security numbers, dates of birth, addresses, and employment information for YP team members and their dependents. Anthem engaged the FBI and Mandiant for investigation, closed vulnerabilities, and provided identity repair and credit monitoring services to affected individuals.
- 🌺Hawaii State AGas victim2015-02-15
Anthem, Inc. reported a data breach to the Hawaii Office of Consumer Protection. The office was notified on 2015/02.15. Breach type: Hackers/Unauthorized Access. 18,206 Hawaii residents were affected. Recovered from the Internet Archive after the notice was removed from the OCP table.
- FEDERALHHS OCRas victim2015-02-13
Anthem Inc., a health plan based in Indiana, reported to HHS OCR on 2015-02-13 (breach report filed 2015-03-13) that cyber-attackers exfiltrated ePHI for approximately 78.8 million individuals between 2014-12-02 and 2015-01-27, discovered on 2015-01-29. Initial access was via spear phishing of an Anthem subsidiary employee, leading to an advanced persistent threat intrusion. Stolen data included names, SSNs, medical identification numbers, addresses, dates of birth, email addresses, and employment information. Anthem agreed to a $16 million settlement and corrective action plan with HHS OCR to resolve potential HIPAA Privacy and Security Rule violations, including failures in enterprise-wide risk analysis, system activity review, incident response, and minimum access controls dating back to 2014-02-18.
- 🐻California State AGas victim2015-02-13
Anthem, Inc. notified California AG that cyber attackers gained unauthorized access to its IT system starting in early December 2014, discovered on January 29, 2015. The breach affected current and former members of Anthem and affiliated Blue Cross/Blue Shield plans. Accessed data included names, DOBs, SSNs, healthcare IDs, addresses, emails, and employment/income data. No credit card or medical claims data was compromised. Anthem engaged the FBI and Mandiant, closed the vulnerability, and provided two years of free identity protection via AllClear ID to affected individuals.
- 🐻California State AGas victim2015-02-10
Packers Sanitation Services, Inc. Ltd. reported a data breach involving its former health insurance provider, Anthem Inc. Hackers gained unauthorized access to Anthem's systems, compromising personal information of approximately 80 million individuals, including PSSI employees. Data exposed included names, SSNs, medical IDs, and employment data. Anthem engaged law enforcement and forensic investigators, offering credit monitoring and identity repair to affected individuals.
- INDIANAHHS OCRas victim2013-08-13
Anthem BCBS of GA reported to HHS OCR on 2013-08-13 a Theft (impermissible disclosure) affecting 5,497 individuals. A CE sales representative used an incorrect group number from an erroneous membership/data file, causing inadvertent disclosure of PHI including demographic information to a business associate. The BA subsequently certified destruction of the PHI. OCR confirmed the CE implemented corrective action including enhanced quality control procedures and counseling of the involved representative.