Back to the archive

The encyclopedia · Software & IT · Operational decision · 2015

Anthem's breach exposed 78.8M health records — the largest healthcare data theft

In 2015, hackers stole 78.8M health records from Anthem, the US health insurer. Names, SSNs, medical IDs and income data were compromised.

Anthem Inc. · 2015-02

What happened

In February 2015, Anthem Inc., one of the largest health insurance companies in the US, disclosed that hackers had accessed its database and stolen approximately 78.8 million customer records. The stolen data included names, Social Security numbers, medical IDs, addresses, dates of birth and income information.

The breach was attributed to a state-sponsored hacking group (believed to be Chinese). The hackers gained access through a phishing email that compromised an employee's credentials, then moved laterally through Anthem's network to the database.

Anthem paid $115 million in a class-action settlement — the largest data breach settlement in history at the time. The case illustrated how healthcare data is uniquely valuable to hackers (it cannot be changed like a credit card number) and how a single phishing email can compromise the most sensitive personal data of tens of millions of people.

Why it happened

  • Hackers stole 78.8M health records via a phishing email that compromised an employee's credentials.
  • The stolen data included SSNs, medical IDs and income information — data that cannot be changed.
  • Anthem paid $115M in a class-action settlement.
  • The breach was attributed to a state-sponsored hacking group.
What it cost78.8M records; $115M settlement; largest health breachcostly

The lesson

Healthcare data is the most valuable data a hacker can steal — because it cannot be changed. A credit card can be cancelled; a Social Security number cannot. The human layer is the weakest link.

Aftermath

Anthem paid $115M and overhauled its security. The case prompted the healthcare industry to strengthen cybersecurity and influenced HIPAA enforcement. It remains one of the largest data breaches in US history.

Sources

spotted an error? The club wants to know.

Comments · 0

    Sign in to join the comments.

    More like this

    Somewhere, someone solved the problem this company failed at. 2nd Opinion →