California Health News

News & Announcements about health insurance in California




  • Home
    • CHN File Explorer
  • About
  • Contact
  • Health Plans
    • Aetna
    • Anthem Blue Cross
    • Blue Shield
    • Centene
    • CoveredCA Small Group
    • CaliforniaChoice
    • Cigna
    • Health Net
    • Kaiser
    • L.A. Care Covered
    • Molina
    • Oscar
    • Sutter Health Plus
    • United Healthcare
    • Valley Health Plan
    • Western Health Advantage
  • Government
    • Affordable Care Act
    • CMS
    • CA DMHC
    • Cal DOI
    • Covered California
      • CalHEERS
      • Certified Agents
    • HHS
    • Healthcare.gov
    • IRS
    • Medicare
      • PDP
      • CMS
    • Medi-Cal

Investigation of major Anthem cyber breach reveals foreign nation behind breach

January 6, 2017 By Kevin Knauss Leave a Comment

California Department of Insurance

SACRAMENTO, Calif. – The California Department of Insurance released today the examination findings and settlement agreement concerning the cyber security breach of health insurance giant Anthem Inc., which compromised 78.8 million consumers’ records. Anthem agreed to make a number of enhancements to its information security systems, and also agreed to provide credit protection to all consumers whose information was compromised. Anthem is paying more than $260 million dollars for security improvements and remedial actions in response to this breach. California Insurance Commissioner Dave Jones was one of seven insurance commissioners leading the national investigation of the Anthem cyber breach.

“This was one of the largest cyber hacks of an insurance company’s customer data,” said Insurance Commissioner Dave Jones. “Insurers have an obligation to make sure consumers’ health and financial information is protected. Insurance commissioners required Anthem to take a series of steps to improve its cybersecurity and provide credit protection for consumers affected by the breach. In this case, our examination team concluded with a significant degree of confidence that the cyber attacker was acting on behalf of a foreign government. Insurers and regulators alone cannot stop foreign government assisted cyber attacks. The United States government needs to take steps to prevent and hold foreign governments and other foreign actors accountable for cyber attacks on insurers, much as the President did in response to Russian government sponsored cyber hacking in our recent presidential election. “
The cyber breach was first discovered by Anthem on January 27, 2015. In early February 2015, Anthem and its affiliates announced the company had suffered a major breach, which compromised 78.8 million consumer records, including records of at least 12 million minors.
An investigation by the insurance commissioners’ examination team and a separate internal investigation by Mandiant, an information security firm hired by Anthem, revealed the data breach began on February 18, 2014, when a user within one of Anthem’s subsidiaries opened a phishing email containing malicious content. Opening the email permitted the download of malicious files to the user’s computer and allowed hackers to gain remote access to that computer and at least 90 other systems within the Anthem enterprise, including Anthem’s data warehouse.
The lead insurance commissioners employed an examination team composed of the cybersecurity firm CrowdStrike and Alvarez & Marsal Insurance and Risk Advisory Services, LLC. The team focused itsĀ investigation on Anthem’s pre-breach response preparedness, the company’s response adequacy at the time of the breach, and their post-breach response and corrective actions.
The team found Anthem had taken reasonable measures prior to the data breach to protect its data and employed a remediation plan resulting in a rapid and effective response to the breach once it was discovered. The team noted Anthem’s exploitable vulnerabilities, worked with Anthem to develop a plan to address those vulnerabilities, and conducted a penetration test exercise to validate the strength of Anthem’s corrective measures. As a result, the team found Anthem’s improvements to its cybersecurity protocols and planned improvements were reasonable.
The team determined with a high degree of confidence the identity of the attacker and concluded with a medium degree of confidence that the attacker was acting on behalf of a foreign government. Notably, the exam team also advised that previous attacks associated with this foreign government have not resulted in personal information being transferred to non-state actors.
Within two weeks of discovering the breach and following discussions with the lead states, Anthem hired AllClear ID, a consumer credit protection company, to offer credit protection services to all breach-affected consumers for a two-year period. Additionally, as a result of this multi-state settlement, Anthem has agreed to offer a credit protection solution to all minors who were under age 18 when the security breach occurred. Consumers affected by the breach, including parents of affected minors, are encouraged to visit www.AnthemFacts.com to learn more about the credit monitoring and identity theft services that Anthem agreed to offer to individuals.

  • Regulatory Settlement Agreement between Anthem, Inc. and the departments of insurance
  • Multistate Target Market Conduct and Financial Examination report of Anthem Inc.
  • The insurance commissioners leading the national investigation included the insurance commissioners for California, Indiana (the principal domiciliary regulator for Anthem and chair of the lead commissioners’ task force), Maine, Missouri, New Hampshire, North Dakota and South Carolina. In addition to the leading state commissioners, 40 other state and territorial insurance commissioners have now joined in the agreement as participating jurisdictions.

 

Filed Under: Anthem Blue Cross, Cal DOI Tagged With: Anthem, Attack, Blue Cross, California, Cyber, Hack

About Kevin Knauss

Independent health insurance agent and Certified Insurance Agent for Covered California. Serving all of California. Editor of Health Plan News for California consumers. Feel free to call him for clarification on items posted on this website at 916-521-7216 or email on his contact page of
www.insuremekevin.com

Advertisement

Advertisement

Comparing Health Plan Video

Health, Insurance, Plan, Comparison

Using a table of in-network providers, hospitals, drugs, and rates to compare health plans

Kevin Knauss

California, Kevin Knauss, Rainbow, LGBT, Insurance, Author, Medicare

Education Before Enrollment

Phone: 916-521-7216

New Medicare Claim Numbers Coming

Medicare, Social Security

New Medicare Claim Numbers

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Kevin Knauss - www.insuremekevin.com - CDI# 0H12644