← Case Files · The Breach Files

2015 · Health insurance

Anthem, 2015: 78.8 million health records and one query that looked wrong

Case file · 4 min read · Published 14 September 2026

People affected
78.8 million people
When it happened
February 2014 – January 2015
Made public
4 February 2015
How they got in
Spear-phishing a subsidiary, then stolen credentials into a data warehouse
Attributed to
Two Chinese nationals indicted by the US Department of Justice in 2019
What it cost
$115 million class settlement, $16 million HIPAA penalty, $39.5 million to state attorneys general

What was exposed: Names · Dates of birth · Social Security numbers · Member ID numbers · Addresses · Email addresses · Employment and income data

The Anthem breach was found because a database administrator looked at a query running under his own account, did not recognise it, and asked about it. Everything else — the largest health data breach in US history at the time, the largest HIPAA penalty ever levied, a federal indictment — followed from that one moment of professional suspicion.

What happened

Anthem was one of the largest health insurers in the United States. Beginning in February 2014, attackers established access to its network and spent roughly a year inside. In late January 2015, the administrator noticed the anomalous query; the investigation that followed established that a data warehouse containing member records had been queried and copied.

Anthem announced the breach on 4 February 2015: 78.8 million people, including current and former members and people covered through affiliated plans in other states. The exposed fields were names, dates of birth, Social Security numbers, member identification numbers, addresses, email addresses and employment and income information.

Clinical data was not taken. That distinction matters, and it is often lost: this was not a leak of diagnoses. It was a leak of the identity layer that sits underneath health coverage, which is arguably the more portable and durable asset.

How they got in

The entry point was a spear-phishing campaign against a subsidiary. At least one employee opened a message and their credentials were captured; from there the attackers escalated and moved laterally until they reached credentials with access to the enterprise data warehouse.

The control that would have stopped it. The California Department of Insurance's examination, and Anthem's own remediation commitments, kept returning to the same theme: privileged access to a warehouse holding tens of millions of member records was reachable with a password alone. Multi-factor authentication on administrative and remote access, and tighter segmentation between the corporate network and the warehouse, are the two controls that recur in every finding. They were not exotic in 2014. They were simply not in place.

In May 2019 the Department of Justice indicted two Chinese nationals over the intrusion and three similar attacks on other US companies. The indictment described the same pattern: tailored phishing emails, a remote access trojan, patient lateral movement, then a bulk extraction of a customer database. Neither defendant has been brought to trial in the United States.

The timeline

  1. February 2014 — A spear-phishing campaign against an Anthem subsidiary succeeds; access is established.
  2. 2014 — The attackers move laterally and obtain credentials reaching the enterprise data warehouse.
  3. Late January 2015 — A database administrator queries an unrecognised query running under his own credentials.
  4. 4 February 2015 — Anthem discloses the breach: 78.8 million people.
  5. January 2017 — A multi-state insurance regulator examination publishes findings on the security failures.
  6. June 2017 — A $115 million class-action settlement, the largest data breach settlement in the US at the time.
  7. October 2018 — A $16 million HIPAA settlement with the Department of Health and Human Services — nearly three times the previous record.
  8. May 2019 — Two Chinese nationals are indicted.
  9. September 2020 — A $39.5 million settlement with state attorneys general.

Why health identity data is different

A stolen payment card has a short, well-managed life. The bank has fraud models, the network has liability rules, and the card can be cancelled. Health identity data has none of that infrastructure.

The member ID plus a name, date of birth and Social Security number is enough to obtain care, prescriptions or equipment in someone else's name. That fraud does not appear on a monthly statement. It appears, if at all, when a bill arrives from a provider the victim has never visited, or when a benefit limit has been exhausted by someone else, or — in the cases that cause real harm — when incorrect information ends up in the victim's own medical record.

Unwinding it is slow, because health records are held by many separate organisations with no central mechanism to correct them, and because privacy law that protects records also makes them harder to inspect and amend after fraud.

What it changed

HIPAA enforcement got teeth. The $16 million settlement reset expectations for what a health data failure costs in the United States. Regulators also made clear in the resolution agreement that the failures were ordinary ones — insufficient risk analysis, inadequate review of system activity, weak access controls — not exotic ones.

Health insurers adopted multi-factor authentication and segmentation at speed. Anthem's own remediation commitments, published as part of the multi-state examination, became a de facto checklist across the sector.

Anomaly review stopped being purely automated. The most-quoted fact about this breach is how it was found. It is used, correctly, as an argument for a culture in which an employee who notices something odd has an obvious, low-friction way to report it and an expectation that it will be taken seriously.

If you were an Anthem member

  1. Read your explanation of benefits statements. They are the only routine mechanism by which medical identity fraud becomes visible. Any provider or service you do not recognise is worth a phone call.
  2. Freeze your credit files. The Social Security numbers in this breach support ordinary financial fraud as readily as medical fraud.
  3. Ask for a copy of your medical records if you suspect misuse, and correct them. Errors introduced by someone else's treatment under your identity can affect your own care.
  4. Treat calls about your coverage as unverified. Anyone who knows your member ID has not proved they are your insurer — what to check before you answer anything.

Checked against every breach on record, against public breach data only. Your address is not sent to us as a form and is not stored — it is handed straight to the lookup tool in your own browser. See the privacy policy.

Questions people ask

Was medical treatment data stolen from Anthem?

No. Anthem reported that clinical and claims information — diagnoses, treatments, test results — was not taken. What was taken was the membership file: names, dates of birth, Social Security numbers, member IDs, addresses and employment data. That is an identity-theft dataset rather than a medical one, which is bad in a different way.

How was the Anthem breach discovered?

A database administrator noticed a query running under his own credentials that he had not run, and raised it. Everything that followed — the investigation, the disclosure, the eventual scope — came from one person questioning something that looked slightly wrong rather than from an automated control.

Why is health insurance data so valuable?

Because it combines a permanent national identifier with enough personal detail to pass identity verification, and because medical identity fraud is slow to detect. A fraudulent credit card shows up on a statement within weeks; fraudulent care billed against your member ID may not surface for years, and unwinding it is far harder.

What penalties followed?

A $115 million class-action settlement in 2017, a $16 million settlement with the US Department of Health and Human Services in 2018 — the largest HIPAA penalty on record at that point — and a $39.5 million settlement with state attorneys general in 2020.

Sources

Read next

Case files are written from the public record: regulatory findings, court filings, company disclosures and contemporaneous reporting, cited above. Figures are the ones the organisation or its regulator finally settled on, which is often not the number first reported — where that differs, the page says so. Disputed accounts are marked as disputed rather than resolved in either direction.

← All case files Breach archive →