ANTHEM INSURANCE COMPANIES, INC.
ent_019eb4832fa30730ca19b0f6c5ba4a86
Disclosures
11
State AG · HHS OCR · 6 jurisdictions
Multi-filing incidents
4
incidents joining 2+ filings here
Max affected reported
461,769
as filed · State AG SC
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- ANTHEM INSURANCE COMPANIES, INC.
- Normalized
- anthem insurance companies— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300JEIWHW95MMXY71
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- anthem.com
- Corporate parent
- Elevance Health, Inc.— per SEC Exhibit 21 filing
Disclosure history (11)newest first
- Massachusetts State AGas victim2025-11-19
Anthem, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-11-19. 1,162 Massachusetts residents were affected.
- Indiana State AGas victim2022-09-27
Anthem Insurance Companies, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2022-05-07 and was reported on 2022-09-27. 1,531 Indiana residents were affected. 13,406 individuals affected in total.
- INDIANAHHS OCRas reporting2021-11-19
Anthem, Inc. reported to HHS on 2021-11-19 a Hacking/IT Incident affecting 6118 individuals. Breached information located on Network Server. The breach compromised PHI including names, addresses, DOB, and treatment info. The CE and BA implemented additional administrative and technical safeguards.
- INDIANAHHS OCRas victim2021-10-15
Anthem Inc. reported to HHS on 2021-10-15 a Hacking/IT Incident affecting 2023 individuals. Breached information located on Network Server. A business associate's subcontractor suffered a ransomware attack affecting ePHI including names, addresses, DOB, and SSNs.
- California State AGas victim2021-10-15
PracticeMax, a vendor for Anthem's VillageHealth program, experienced a ransomware attack between April 17 and May 5, 2021. Unauthorized access to a server containing Protected Health Information (PHI) was discovered on May 1, 2021. Affected data includes names, dates of birth, addresses, phone numbers, Anthem member IDs, and clinical kidney care data. PracticeMax engaged forensic investigators, rebuilt systems, enhanced firewalls, and offered 24 months of credit monitoring via Epiq.
- Montana State AGas reporting2019-03-20
Anthem Insurance Companies, Inc. notified Montana AG that its vendor, LCP Transportation, experienced a security incident involving unauthorized access to an employee email account between July and September 2018. The breach was discovered on January 15, 2019. Impacted data included names, Anthem IDs, addresses, DOBs, and PHI. LCP engaged forensic investigators and law enforcement. Anthem provided one year of credit monitoring.
- New Hampshire State AGas victim2015-06-01
YP Holdings LLC notified NH AG of the Anthem, Inc. data breach affecting 2 NH residents. Anthem, a third-party administrator, suffered a sophisticated cyber attack in Dec 2014, discovered Jan 5, 2015. Data accessed included names, SSNs, DOB, and health IDs. Anthem engaged FBI and Mandiant, offering credit monitoring.
- New Hampshire State AGas victim2015-03-20
Anthem, Inc. suffered a sophisticated external cyber-attack discovered on Jan 29, 2015. BCBSMA notified Nuance Medical Plan participants on Mar 2, 2015. Data accessed included names, DOB, gender, member IDs, addresses, phone, email, and employment info. No SSN or financial data compromised. Anthem offered 2 years of credit monitoring.
- New Hampshire State AGas victim2015-03-18
Anthem, Inc. notified the NH DOJ of a cyber attack discovered Jan 29, 2015, with unauthorized access occurring since early Dec 2014. The breach impacted members of Anthem and affiliated BCBS plans, exposing PII, SSNs, and PHI. Anthem engaged Mandiant and cooperated with the FBI. United Rentals, Inc. was notified as a plan sponsor.
- South Carolina State AGas victim2015-03-06
Anthem, Inc. disclosed a cybersecurity incident where cyber attackers gained unauthorized access to its IT system in early December 2014. Discovered on January 29, 2015, the breach exposed personal information including names, SSNs, DOBs, and employment data for current and former members of affiliated health plans and other BCBS plans. Anthem engaged the FBI and Mandiant, closed the vulnerability, and provided two years of identity protection services.
- New Hampshire State AGas victim2015-02-18
Anthem, Inc. notified New Hampshire of a cyber attack discovered on Jan 29, 2015. Attackers gained unauthorized access using valid credentials starting in early Dec 2014. Impacted data included names, SSNs, DOBs, and employment info. Anthem engaged the FBI and Mandiant, and is providing 2 years of free identity protection services to affected members.
Supply-chain cascadesreviewed and confirmed
- ANTHEM INSURANCE COMPANIES, INC. supply-chain incident (2015)2015-02-10 – 2015-06-0112 organizations linked