Security Risk Analysis

Premera Blue Cross: $6.85M HIPAA Settlement

Encryption failures and risk analysis gaps in the 10.4 million record breach

Quick Answer

Premera Blue Cross failed to implement encryption for sensitive electronic health information and conduct adequate risk analysis, resulting in a breach affecting 10.4 million individuals and a $6.85 million OCR settlement in 2019.

Case Overview

In January 2015, Premera Blue Cross discovered unauthorized access to its systems affecting approximately 10.4 million individuals. The breach exposed personal information including names, dates of birth, Social Security numbers, medical information, financial account information, and prescription drug history.

The OCR investigation revealed that Premera failed to implement encryption for electronic PHI in transit and at rest, did not conduct adequate risk analysis, and lacked sufficient access controls. The organization was notified of security vulnerabilities but failed to remediate them promptly. In June 2019, Premera agreed to pay $6.85 million in settlement and implement comprehensive security improvements.

10.4M
Individuals Affected
$6.85M
Settlement Amount
2019
Settlement Year
2nd Largest
At Time of Settlement

What Went Wrong

Lack of Encryption

Inadequate Risk Analysis

Access Control Failures

Vulnerability Management Gaps

OCR Findings

The OCR investigation identified violations across multiple areas of the HIPAA Security Rule:

Administrative Safeguards Violations

Technical Safeguards Violations

Physical Safeguards Issues

Investigation Scope

OCR examined Premera's security policies, risk analysis documents, system configurations, access control mechanisms, encryption implementation, audit logs, and incident response procedures.

Settlement Details

Financial Resolution

Corrective Action Plan (CAP)

Premera was required to implement:

Ongoing Oversight

OCR retained authority to verify compliance with settlement terms and conduct periodic audits to ensure sustained implementation of security measures.

Lessons Learned

Encryption is Non-Negotiable

Premera's failure to implement encryption across systems represented a fundamental gap in HIPAA technical safeguards. Encryption significantly reduces breach impact and should be implemented as standard practice rather than exception-based.

Risk Analysis Must Drive Action

Identifying risks through risk analysis is only the first step. Premera's analysis identified vulnerabilities but lacked follow-through on remediation, demonstrating that risk assessment without decisive action is ineffective.

Database Security Requires Specialized Controls

Database access was a key vulnerability in the Premera breach. Specialized database activity monitoring, encryption of database contents, and database-level access controls are essential for protecting large repositories of PHI.

Vulnerability Management Cannot Be Optional

The breach involved exploitation of known vulnerabilities that had not been patched. A formal vulnerability management program with assessment, prioritization, and remediation timelines is necessary to maintain security posture.

Delayed Remediation Increases Risk

Known issues that were not promptly addressed created opportunities for exploitation. Security remediation should be prioritized based on risk severity with defined timelines for completion.

Prevention Checklist

Encryption Program

Implement encryption for all electronic PHI in transit using TLS/SSL
Encrypt data at rest in databases, file systems, and backups
Establish encryption key management procedures and secure storage
Maintain inventory of all systems containing PHI and their encryption status

Risk Analysis and Management

Conduct annual comprehensive risk analysis of all systems and data
Identify and prioritize risks based on likelihood and impact
Develop and track remediation plans with defined timelines
Document all risk assessment activities and management decisions

Database Security

Implement database activity monitoring and logging
Apply principle of least privilege to database users
Use role-based access control aligned with job functions
Regularly review database access and remove unnecessary permissions

Vulnerability Management

Establish formal vulnerability assessment program with regular scans
Prioritize and track remediation of identified vulnerabilities
Implement timely patching for all systems and applications
Conduct penetration testing to validate security controls

Frequently Asked Questions

What was the attack vector in the Premera breach? +

The Premera breach involved unauthorized database access that exploited known vulnerabilities in their systems. Attackers were able to maintain persistence within the network and access multiple databases containing PHI. The lack of encryption, weak access controls, and insufficient monitoring allowed the attackers to exfiltrate large volumes of sensitive information without timely detection.

Why was encryption so critical to this case? +

Under HIPAA's Security Rule, encryption is one of the most effective technical safeguards for protecting electronic PHI. Even if an unauthorized user gains database access, encrypted data cannot be read without the encryption key. Premera's lack of encryption meant that once attackers gained access, they could easily read and exfiltrate sensitive information. The breach would have had significantly less impact if data had been encrypted.

How long did the breach go undetected? +

The Premera breach was discovered in January 2015, but forensic investigation determined that unauthorized access occurred over several months prior. The extended timeframe between breach occurrence and detection was attributed to insufficient monitoring and logging mechanisms that would have alerted the organization to unauthorized database access.

What did Premera do to remediate after the breach? +

Beyond the settlement obligations, Premera conducted forensic investigations, notified affected individuals, offered credit monitoring services, and implemented comprehensive security improvements. These included enterprise-wide encryption deployment, enhanced access controls, improved monitoring systems, and an ongoing security assessment program. Premera also engaged third-party security auditors to validate the effectiveness of remediation efforts.

Strengthen Your Encryption Posture

Evaluate whether your organization has comprehensive encryption covering all systems containing electronic PHI, or identify gaps that could lead to enforcement action.

Conduct Your Security Assessment