Anthem health insurer breach affecting tens of millions of individuals
Anthem disclosed a cyberattack that exposed personal information of approximately 78.8 million current and former members. U.S. authorities later brought charges in connection with the breach, and regulators announced major financial settlements, including a record HIPAA settlement with HHS OCR and a multistate attorneys general settlement. These outcomes highlight substantial regulatory and legal financial consequences for large-scale healthcare data breaches.
First reported February 4, 2015Breachhigh overall confidence
DOJ announced charges against an alleged member of a China-based hacking group connected to the Anthem breach; final legal outcomes may vary by defendant and are not summarized here.
CVEs and ATT&CK
No CVE or ATT&CK association is captured in this curated record.
Mitigations
Now
Enforce phishing-resistant MFA for workforce and privileged accountsReduces successful account takeovers from stolen passwords and common social engineering techniques.
Soon
Harden helpdesk and password reset workflowsPrevents attackers from using social engineering to reset MFA or regain access via the identity recovery channel.
Later
Apply conditional access and session risk controls (device posture, geo, impossible travel)Limits account abuse by requiring stronger signals for high-risk sign-ins and reducing lateral access after compromise.
Detection ideas
Alert on anomalous authentication patterns
Flag first-time device logins, new geo/ASN, impossible travel, and sign-ins immediately followed by privilege escalation or access to sensitive apps.