Premera Blue Cross of Washington state, Oregon and Alaska hit by sophisticated hack this January, with up to 11M affected by breach
Context & Ripple Effects
Premera's January intrusion lands three weeks after hackers took account information on as many as 80 million Anthem customers, the nation's second-largest health insurer — and days after [[a:826744|Anthem disclosed the blast radius extended to up to 18.8 million additional Blue Cross Blue Shield members]]. The pattern is now unmistakable: the same month, CareFirst disclosed a June 2014 attack touching 1.1 million DC-area customers.
That makes Premera the third Blue Cross-affiliated plan hit in roughly six weeks, and its footprint spans three states — Washington, Oregon and Alaska — putting up to 11 million members in scope. The coverage arc runs straight through Excellus BCBS's 2013 hack and ultimately to [[a:878005|UnitedHealth's confirmation that over 100 million people had data stolen from Change Healthcare]], so far the largest US healthcare data breach.
First-order effects
- Up to 11 million Premera members in Washington, Oregon and Alaska face exposure of personal and account information, joining the tens of millions already notified through the Anthem and CareFirst breaches.
- Premera inherits the full breach-response burden the other Blue Cross plans are carrying — forensics, member notifications, and credit-monitoring commitments — while regulators in its three states open their own lines of questioning.
Second-order effects
- The cluster of hits across nominally independent Blue Cross licensees pushes scrutiny onto the shared systems and security baselines common to the Blue Cross Blue Shield association rather than any single plan's IT shop.
- Competing regional insurers now face pressure to proactively audit and disclose — the sequence shows each new breach (Anthem, then Premera, then Excellus's retroactive 2013 disclosure) forcing peers to re-examine their own incident histories before someone else does it for them.
Third-order effects
- If the pattern holds, health insurers consolidate as the highest-value target class for attackers — account data, claims history, and identifiers at national scale — pushing the industry toward treating breach readiness as core infrastructure, the trajectory that ends in the nine-figure Change Healthcare toll.
- Regulators' exposure grows alongside: state-level oversight of health data security becomes a standing function, since each successive multi-million-member disclosure raises the political cost of leaving insurer defenses to self-certification.
The trend: US healthcare insurers are being systematically targeted for their troves of identity and claims data, with each breach raising both the scale of exposure and the regulatory stakes for the whole sector.