Desk live·
ForensicPost
Insurance/Health/File 15-0520

CareFirst Found a 2014 Intrusion Affecting 1.1 Million Members While Checking for Anthem’s

The Maryland insurer discovered an 11-month-old compromise only because the Anthem and Premera breaches prompted a review. Passwords and Social Security numbers were not in the database. The litigation that followed set the standard for who can sue.

Constructed geometry · not a chart of case data
JurisdictionUSABaltimorethe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetCareFirst BlueCross BlueShield
ActorUnattributed
D. Kennedy9 min readConfidence: high4 sources reviewed

CareFirst BlueCross BlueShield said on May 20, 2015, that attackers had gained access to a single database in June 2014, exposing names, birth dates, email addresses and subscriber identification numbers for about 1.1 million current and former members in Maryland, Virginia and the District of Columbia. The insurer found the intrusion in spring 2015 during a security review it began after the Anthem and Premera breaches became public.

Passwords were encrypted and stored separately, the company said. Social Security numbers, medical claims, employment information and payment data were held elsewhere and were not reached.

Found By Looking For Someone Else’s Breach

CareFirst was the third Blue Cross plan in four months to disclose an intrusion, and the second to discover one only because a competitor had been hit. Premera, filed at 15-0317, found its own compromise the same way. The pattern says something about detection in the sector at the time: a year-old foothold went unnoticed until an outside event prompted a search for it.

Attribution was never made by the company. KrebsOnSecurity reported that researchers at ThreatConnect had found lookalike domains, including careflrst[.]com, registered in April 2014 by the same bulk registrant behind the we11point[.]com and prennera[.]com domains used against Anthem and Premera. That is a researcher inference, and it is carried here as one.

A Smaller Field List, And A Larger Legal Footprint

By the fields exposed, CareFirst is among the least severe of the 2015 insurer breaches. By its effect on the law, it is the most consequential. Members sued in the District of Columbia within weeks. The district court dismissed the case in 2016 on the ground that no plaintiff had shown actual harm.

On Aug. 1, 2017, the D.C. Circuit reversed. In Attias v. CareFirst the court held that a substantial risk of future identity theft was enough to give breach victims standing to sue. The Supreme Court declined to hear CareFirst’s appeal. The ruling has been cited in nearly every large data-breach class action since. The underlying case was still pending nine years after the intrusion: a contract class was certified in March 2024 after earlier rulings had dismissed the consumer-protection claims for lack of evidence that anyone’s identity had been stolen.

What The Record Shows A Decade On

No federal health-privacy settlement was ever announced, and no individual harm was proved in court. What the file documents is a foothold that lasted 11 months undetected, a discovery driven by the news rather than by monitoring, and a legal doctrine that outlived the data.

How we reported this

Compiled from CareFirst’s statement as reported, the D.C. Circuit’s 2017 opinion and later case coverage, listed below. The 1.1 million figure is the company’s. Attribution to the Anthem actors is a researcher inference and is labelled as one. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Carefirst Blue Cross Breach Hits 1.1MKrebsOnSecurity
  2. CareFirst Says Hack May Have Exposed Data of 1.1 MillionNBC News
  3. Attias v. CareFirst, Inc., No. 16-7108 (D.C. Cir. 2017)Justia
  4. Contract Class Certified in CareFirst Data Breach Lawsuit 9 Years After BreachHIPAA Journal
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary