FineME
Back to Cases
cybersecurityHealthcare · 2018

Anthem Inc.

Anthem Inc. agreed to pay $16 million — the largest HIPAA settlement in history at the time — following a 2015 cyberattack that compromised the electronic protected health information of approximately 78.8 million individuals, the largest healthcare data breach in US history. HHS OCR found Anthem failed to conduct an enterprise-wide HIPAA security risk analysis, failed to implement appropriate information system activity review, and had insufficient technical controls to identify and respond to suspicious network activity prior to the breach. The settlement also required a comprehensive corrective action plan monitored for two years.

Fine Imposed€14.7M
Authority

HHS-OCR-US

Regulation

Key Takeaways
  • An enterprise-wide HIPAA security risk analysis is a non-negotiable foundational requirement — its absence is itself a HIPAA violation, and failure to review system activity logs deprives organisations of the ability to detect breaches before they escalate.