Desk live·
ForensicPost
Insurance/Exposure/File 10-0623

WellPoint Left 612,402 Insurance Applications Reachable Online for Five Months After an Upgrade

A software update to the insurer’s application tracker broke its authentication. A consumer told the company twice. The federal settlement of $1.7 million came three years later, and Indiana added $100,000 for the delay in telling anyone.

Constructed geometry · not a chart of case data
JurisdictionUSAIndianapolisthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetWellPoint applicants
ActorUnattributed
S. Rosler8 min readConfidence: high3 sources reviewed

Between Oct. 23, 2009, and March 7, 2010, an online application tracker run by WellPoint, then the largest U.S. health insurer by membership, allowed individual insurance applications to be viewed without proper authentication. The applications held names, addresses, Social Security numbers, financial details and health information. The Department of Health and Human Services put the affected population at 612,402.

The weakness was introduced by a software upgrade to the system’s authentication. A consumer notified WellPoint on Feb. 22, 2010, and again on March 8. The company secured the site after the second notice and began notifying applicants on June 18, 2010.

The Fix That Was Never Checked

HHS found three failures when it announced a $1.7 million settlement on July 11, 2013: no adequate policies for authorising access, no technical evaluation after the upgrade and no safeguards to verify who was requesting a record. The company had called the exposure human error. The regulator’s finding was narrower and more useful: a change was made to an authentication layer and nobody tested it.

A State Penalty For The Silence

Indiana’s attorney general sued in late 2010, not over the exposure but over the delay in reporting it. The state said WellPoint had known since February and told nobody until June. The July 2011 settlement paid $100,000 to a consumer fund and offered two years of credit monitoring. WellPoint admitted the notification failure.

The two actions describe the two halves of the sector’s obligation. One regulator penalised the control that failed. The other penalised the months in which applicants could have protected themselves and were not told they needed to.

How we reported this

Compiled from the HHS resolution agreement and reporting of the Indiana action, listed below. The 612,402 figure is the federal regulator’s; earlier state figures were lower and are not used. No attacker is alleged; this was an exposure. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. WellPoint Resolution AgreementU.S. Department of Health and Human Services
  2. Wellpoint Agrees to $1.7 Million Settlement for HIPAA ViolationsHIPAA Journal
  3. WellPoint Settles Over Data BreachInfoRiskToday
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary