Blue Shield of California reported a data breach affecting approximately 4.7 million people, placing it among the largest healthcare exposures of 2025.
Health Insurers Hold The Join Nobody Else Has
A provider knows what it treated. An insurer knows everything it paid for — every provider seen, every prescription filled, every procedure claimed, across every organisation a member visited.
That is a more complete medical history than any single clinician holds, assembled for adjudication rather than for care. It is the point this desk made about Allianz Life at 26-0610, in a system where the insurer sees the whole pathway.
Not Every Large Exposure Is An Intrusion
This database contains several eight-figure exposures with no attacker: the misconfigured database at IDMerit in 26-0219, the accidental publication at 26-0428, the aggregated credential stores at 26-0615 and 25-0620.
The reason we file them identically is the one set out at 26-0428: the database records what happened to data. From the position of an affected member, the distinction between an intrusion and a configuration failure is invisible and irrelevant.
Graded medium: the affected figure is well established; the mechanism has not been characterised consistently in the material we reviewed, and we are not asserting one.
Compiled from public reporting, listed below. The exposure mechanism is not established in the sources we reviewed and we do not speculate on it. Corrections: corrections@forensicpost.com.
- These are the biggest health data breaches in the first half of 2025Chief Healthcare Executive
- Biggest healthcare data breaches reported in 2025, so farTechTarget