Premera Blue Cross: $6.85M HIPAA Settlement
Encryption failures and risk analysis gaps in the 10.4 million record breach
Quick Answer
Premera Blue Cross failed to implement encryption for sensitive electronic health information and conduct adequate risk analysis, resulting in a breach affecting 10.4 million individuals and a $6.85 million OCR settlement in 2019.
Case Overview
In January 2015, Premera Blue Cross discovered unauthorized access to its systems affecting approximately 10.4 million individuals. The breach exposed personal information including names, dates of birth, Social Security numbers, medical information, financial account information, and prescription drug history.
The OCR investigation revealed that Premera failed to implement encryption for electronic PHI in transit and at rest, did not conduct adequate risk analysis, and lacked sufficient access controls. The organization was notified of security vulnerabilities but failed to remediate them promptly. In June 2019, Premera agreed to pay $6.85 million in settlement and implement comprehensive security improvements.
What Went Wrong
Lack of Encryption
- Electronic PHI was stored without encryption in multiple systems
- Data in transit was not encrypted across network communications
- Backup systems contained unencrypted sensitive information
- No comprehensive encryption standard was implemented organization-wide
Inadequate Risk Analysis
- Risk analysis did not comprehensively identify all PHI repositories
- Vulnerabilities in systems were not properly assessed or prioritized
- Remediation of identified risks was delayed or incomplete
- No documented periodic reassessment of security risks
Access Control Failures
- Excessive user privileges across database systems
- Weak password policies and authentication mechanisms
- Insufficient monitoring of database access and modifications
- Lack of unique user identification for system access
Vulnerability Management Gaps
- Known vulnerabilities identified by internal scans were not remediated
- Patches and updates were not applied promptly
- No formal vulnerability assessment program was in place
OCR Findings
The OCR investigation identified violations across multiple areas of the HIPAA Security Rule:
Administrative Safeguards Violations
- § 164.308(a)(1) - Inadequate security management process and risk analysis
- § 164.308(a)(4) - Incomplete information system activity review and security incident procedures
- § 164.308(a)(7) - Failure to implement workforce security safeguards
Technical Safeguards Violations
- § 164.312(a)(2) - Inadequate access controls including unique user identification and emergency access procedures
- § 164.312(b) - Insufficient audit controls and logging mechanisms
- § 164.312(c) - Lack of integrity controls to detect and prevent unauthorized modification
- § 164.312(e) - Missing encryption for electronic PHI in transit and at rest
Physical Safeguards Issues
- § 164.310(a)(2) - Inadequate facility access controls
Investigation Scope
OCR examined Premera's security policies, risk analysis documents, system configurations, access control mechanisms, encryption implementation, audit logs, and incident response procedures.
Settlement Details
Financial Resolution
- Civil Monetary Penalties: $6.85 million
- Payment Timeline: Structured settlement agreement with OCR
- Covered Entity Liability: Full responsibility for breach
Corrective Action Plan (CAP)
Premera was required to implement:
- Organization-wide encryption of all electronic PHI in transit and at rest
- Comprehensive risk analysis covering all systems and data stores
- Enhanced access control mechanisms including multi-factor authentication
- Improved monitoring and alerting for database access and modifications
- Vulnerability assessment and patch management program
- Enhanced incident response procedures and security incident investigation
- Workforce security training and awareness program
- Third-party audit and assessment mechanisms
Ongoing Oversight
OCR retained authority to verify compliance with settlement terms and conduct periodic audits to ensure sustained implementation of security measures.
Lessons Learned
Encryption is Non-Negotiable
Premera's failure to implement encryption across systems represented a fundamental gap in HIPAA technical safeguards. Encryption significantly reduces breach impact and should be implemented as standard practice rather than exception-based.
Risk Analysis Must Drive Action
Identifying risks through risk analysis is only the first step. Premera's analysis identified vulnerabilities but lacked follow-through on remediation, demonstrating that risk assessment without decisive action is ineffective.
Database Security Requires Specialized Controls
Database access was a key vulnerability in the Premera breach. Specialized database activity monitoring, encryption of database contents, and database-level access controls are essential for protecting large repositories of PHI.
Vulnerability Management Cannot Be Optional
The breach involved exploitation of known vulnerabilities that had not been patched. A formal vulnerability management program with assessment, prioritization, and remediation timelines is necessary to maintain security posture.
Delayed Remediation Increases Risk
Known issues that were not promptly addressed created opportunities for exploitation. Security remediation should be prioritized based on risk severity with defined timelines for completion.
Prevention Checklist
Encryption Program
Risk Analysis and Management
Database Security
Vulnerability Management
Frequently Asked Questions
The Premera breach involved unauthorized database access that exploited known vulnerabilities in their systems. Attackers were able to maintain persistence within the network and access multiple databases containing PHI. The lack of encryption, weak access controls, and insufficient monitoring allowed the attackers to exfiltrate large volumes of sensitive information without timely detection.
Under HIPAA's Security Rule, encryption is one of the most effective technical safeguards for protecting electronic PHI. Even if an unauthorized user gains database access, encrypted data cannot be read without the encryption key. Premera's lack of encryption meant that once attackers gained access, they could easily read and exfiltrate sensitive information. The breach would have had significantly less impact if data had been encrypted.
The Premera breach was discovered in January 2015, but forensic investigation determined that unauthorized access occurred over several months prior. The extended timeframe between breach occurrence and detection was attributed to insufficient monitoring and logging mechanisms that would have alerted the organization to unauthorized database access.
Beyond the settlement obligations, Premera conducted forensic investigations, notified affected individuals, offered credit monitoring services, and implemented comprehensive security improvements. These included enterprise-wide encryption deployment, enhanced access controls, improved monitoring systems, and an ongoing security assessment program. Premera also engaged third-party security auditors to validate the effectiveness of remediation efforts.
Strengthen Your Encryption Posture
Evaluate whether your organization has comprehensive encryption covering all systems containing electronic PHI, or identify gaps that could lead to enforcement action.
Conduct Your Security Assessment