Anthem Data Breach: $16M HIPAA Settlement
Analysis of the largest healthcare data breach and OCR enforcement action in HIPAA history
Quick Answer
Anthem failed to conduct adequate risk analysis and implement reasonable safeguards, resulting in the compromise of 78.8 million records and a $16 million OCR settlement in 2015—the largest HIPAA settlement at the time.
Case Overview
In 2014, Anthem Inc., one of the nation's largest health insurance companies, suffered a massive data breach affecting approximately 78.8 million individuals across multiple insurance brands including BlueCross BlueShield and Medicaid members. The breach exposed personal information including names, dates of birth, Social Security numbers, medical information, and insurance identification numbers.
The Office for Civil Rights (OCR) investigation revealed systemic failures in the company's security infrastructure and lack of adequate risk assessment practices. In September 2015, Anthem agreed to pay $16 million in settlement funds and implement comprehensive corrective action plans.
What Went Wrong
Inadequate Risk Analysis
- Failed to identify clear unencrypted information assets containing PHI
- Did not assess likelihood and impact of potential security incidents
- Risk analysis did not cover all systems and data repositories
- No documented periodic reassessment of risks
Insufficient Encryption Implementation
- Backup tapes and systems stored unencrypted PHI
- No consistent encryption of electronic PHI in transit or at rest
- Legacy systems remained without encryption despite identified risks
Access Control Deficiencies
- Excessive user privileges across systems
- Weak authentication mechanisms allowing unauthorized access
- Limited monitoring and logging of system access
Third-Party Management Issues
- Inadequate oversight of service providers and contractors
- Limited requirements in business associate agreements
- Insufficient audit and monitoring of BA compliance
OCR Findings
The OCR investigation documented the following HIPAA violations:
Security Rule Violations (45 CFR § 164.308-316)
- § 164.308(a)(1) - Inadequate security management process and risk analysis
- § 164.312(a)(2) - Deficient access controls and unique user identification
- § 164.312(a)(2)(i) - Weak authentication mechanisms
- § 164.312(b) - Incomplete audit controls and accountability mechanisms
- § 164.314(a)(2) - Inadequate business associate agreements and oversight
Breach Notification Rule Violations (45 CFR § 164.400-414)
- § 164.400 - Failure to provide timely notification to affected individuals
- § 164.404 - Delayed notification of breach of unsecured PHI
Investigation Scope
OCR reviewed Anthem's security practices, risk analysis documentation, encryption implementation, access controls, business associate management, and incident response procedures from 2009-2014.
Settlement Details
Financial Resolution
- Settlement Amount: $16 million (largest HIPAA settlement at time)
- Payment Structure: Civil monetary penalties for Security Rule violations
- Notification Costs: Additional compensation for breach notification expenses
Corrective Action Plan
Anthem was required to implement comprehensive improvements including:
- Comprehensive security risk analysis and periodic reassessment
- Encryption of all electronic PHI in transit and at rest
- Enhanced access controls and multi-factor authentication
- Improved monitoring and logging of system access
- Strengthened business associate agreement management and oversight
- Enhanced audit and compliance monitoring programs
- Regular security training for all workforce members
- Independent security assessments and penetration testing
Ongoing Monitoring
OCR retained authority to conduct follow-up audits and compliance reviews to ensure implementation and sustainability of corrective actions.
Lessons Learned
Risk Analysis is Foundational
Anthem's failure to conduct adequate risk analysis meant vulnerabilities went unidentified and unaddressed. A thorough, documented risk analysis that is periodically updated is essential for identifying all PHI assets and potential security gaps.
Encryption is Critical
The breach exposed unencrypted personal information across backup systems, databases, and communications channels. Encryption of PHI both in transit and at rest significantly reduces breach impact and can assist in demonstrating reasonable safeguards under HIPAA Safe Harbor.
Access Control Must Be Granular
Broad access privileges and weak authentication enabled the attackers to maintain persistence and exfiltrate records. Implementing role-based access control, least privilege principles, and multi-factor authentication are essential controls.
Business Associate Management Matters
Third-party service providers represent an extended security boundary. Strong BAAs with specific security requirements, regular audits, and oversight are necessary to manage risks across the entire business ecosystem.
Size Does Not Provide Exemption
As a large, well-resourced organization, Anthem faced high expectations for security maturity. HIPAA applies the same standards regardless of organization size, but larger entities have more resources to implement robust controls.
Prevention Checklist
Risk Management
Technical Safeguards
Access Controls
Third-Party Management
Frequently Asked Questions
Anthem discovered the breach during incident response investigations after detecting suspicious network activity. The exact timeline and detection methods were part of OCR's investigation. The company subsequently conducted a forensic investigation to determine the scope of the incident, which revealed the breach had occurred in December 2014 but went undetected for approximately six weeks.
The Anthem case set a precedent for the highest HIPAA settlement at the time and reinforced OCR's focus on risk analysis and encryption. It demonstrated that large, sophisticated organizations cannot rely on size or complexity as excuses for security failures. The case also highlighted that OCR places significant emphasis on whether organizations conducted reasonable risk assessment before incidents occur.
Yes, Anthem was required to provide breach notification to all individuals whose unsecured PHI was compromised. The breach notification process was one of the largest in healthcare history. Notification included details about the breach, steps individuals should take to protect themselves, and information about credit monitoring services offered by Anthem.
The Anthem case accelerated industry-wide adoption of encryption, enhanced risk analysis processes, and improved access control mechanisms. Healthcare organizations increased budget allocation for security infrastructure and governance. The case also emphasized importance of documented risk assessment as a foundational HIPAA compliance element.
Assess Your HIPAA Risk Profile
Learn how your organization stacks up against HIPAA Security Rule requirements and identify gaps that could lead to enforcement action.
Start Your Security Risk Analysis