Premera Blue Cross announced on March 17, 2015, that attackers had gained access to its systems on May 5, 2014, and remained until March 6, 2015. The company said up to 11 million people were affected; regulators later used 10.4 million, including 6.4 million Washington residents. The data included names, birth dates, Social Security numbers, member identification numbers, bank account information and medical claims and clinical information.
Premera had discovered the intrusion on Jan. 29, 2015. It disclosed 47 days later. The attackers were still inside for the first five weeks of that interval.
The Warning Before The Breach
Washington’s attorney general found that auditors had told Premera about unpatched vulnerabilities before the intrusion began. The route in was a phishing email that installed malware, the same opening as Anthem, filed at 15-0204, and the company found the compromise the same week Anthem found its own. Plaintiffs’ filings described an advanced persistent threat group originating from China. No charges were brought and no government made the attribution.
Three Settlements
Thirty attorneys general settled for $10 million on July 11, 2019, with $5.4 million to Washington. The states alleged that Premera had misrepresented its security to consumers before and after the breach. The consent decree required a chief information security officer, annual reviews and a compliance program.
The class action settled for $74 million with final approval on March 2, 2020: a $32 million fund with a $50 default payment and up to $10,000 for documented losses, plus $42 million in required security spending through 2022. The Department of Health and Human Services settled for $6.85 million on Sept. 25, 2020, then the second-largest health-privacy penalty, citing the absence of an enterprise-wide risk analysis and failures in audit controls.
The Clinical Field
Anthem’s breach was larger. Premera’s was worse per record. Bank account numbers and clinical data sit next to the Social Security number in a health plan’s claims system, and this file is the first in the corpus where all three left together at scale. The pattern repeated at Excellus, filed at 15-0909, and a decade later at Star Health, filed at 24-0920.
Compiled from the Washington attorney general’s announcement, the HHS resolution, settlement counsel’s account of final approval and contemporaneous reporting, listed below. The 11 million figure was Premera’s in 2015; 10.4 million is the regulators’. Chinese attribution is a plaintiffs’ allegation and is labelled as one. Graded high. Corrections: corrections@forensicpost.com.
- Attorney General Ferguson’s investigation of Premera data breach results in $10 million settlementWashington State Attorney General
- Premera Blue Cross resolution agreementU.S. Department of Health and Human Services
- Judge Simon Grants Final Approval of Premera SettlementTousley Brain Stephens
- Health Insurance Provider Premera Discloses Data BreacheWeek