Anthem Settles with OCR for $16M for 2015 Data Breach

Robinson+Cole Data Privacy + Security Insider
Contact

The Department of Health and Human Services Office for Civil Rights (OCR) announced this week that it has settled the largest health care data breach for the largest enforcement fine in history. OCR settled the massive data breach Anthem suffered in 2015 for $16 million—a substantially larger fine than any others assessed by OCR for HIPAA violations. The data breach included the names, birth dates, and Social Security numbers of close to 80 million individuals. The data breach was caused when hackers spear-phished an Anthem employee and was able to access the system and the individuals’ health and personal information.

Following Anthem’s notification of the data breach, which is required by regulation, the OCR commenced an investigation and alleged that Anthem violated HIPAA when it failed to run risk analyses, lacked procedures to regulatory review activity on its system, failed to detect or respond to security incidents and failed to have appropriate access controls in place. According to the OCR, “Unfortunately, Anthem failed to implement appropriate measures for detecting hackers who had gained access to their system to harvest passwords and steal people’s private information.” Anthem denies liability in the Agreement with OCR.

According to the OCR, in addition to the payment of the fine, Anthem will take “substantial” measures to assess and monitor its cyber risks.

This settlement follows Anthem’s settlement with consumers in June 2017 for $115 million.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Robinson+Cole Data Privacy + Security Insider | Attorney Advertising

Written by:

Robinson+Cole Data Privacy + Security Insider
Contact
more
less

Robinson+Cole Data Privacy + Security Insider on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide