Hackers obtain account information of as many as 80M customers of Anthem, nation's 2nd largest health insurer; medical info not stolen
Massive breach at health care company Anthem Inc. — SAN FRANCISCO - As many as 80 million customers of the nation's second largest health insurance company …
Context & Ripple Effects
In early February 2015, Anthem disclosed that hackers obtained account information — names, birthdates, SSNs — for as many as 80 million members of the nation's second-largest health insurer, with medical records apparently untouched. Within weeks the perimeter widened: up to 18.8 million Blue Cross Blue Shield customers were added to the affected pool, and attribution reporting pointed toward a China-sponsored group, with Symantec later identifying Anthem as a secondary target of the Black Vine espionage operation.
The breach became a template for healthcare cyber liability: in 2017 Anthem agreed to a $115M class action settlement, one of the largest of its kind. The pattern has since escalated rather than faded — UnitedHealth's Change Healthcare attack surpassed it at over 100 million people, and hospital operator Ascension's 2024 breach exposed another ~5.6 million patients and staff.
First-order effects
- Up to 80 million current and former Anthem members face identity-theft exposure from stolen names, birthdates, and Social Security numbers — data that, unlike payment cards, cannot be reissued.
Second-order effects
- The scope kept expanding beyond Anthem's own books to Blue Cross Blue Shield members and non-customers, forcing affiliated plans into shared notification, credit-monitoring, and legal-defense costs that culminated in the $115M settlement.
Third-order effects
- With Change Healthcare and Ascension following, breaches of this scale are pushing health insurers and hospitals toward treating member data as their single largest unpriced liability — driving consolidation of security spend, board-level accountability, and regulatory pressure across US healthcare.
The trend: US healthcare is becoming the most systematically breached consumer-data sector, where each mega-breach — Anthem, Change Healthcare, Ascension — raises the settlement, regulatory, and security baseline for every insurer that follows.