Anthem Information Security Case Study

442 Words1 Page

Anthem is one of the United States’ largest health insurance companies. It is the largest managed health care company in the Blue Cross and Blue Shield Association. In February of 2015, hackers stole the names, social security numbers, medical IDs, physical addresses, e-mail addresses, employment information, income data, birth dates and other personal information of about 80 million Anthem and other Blue Cross and Blue Shield members and former members. It is believed to be the largest cyber-attack that has ever occurred in health care history. It has been described as a very sophisticated attack. The source of this attack is still unknown, but several reports have linked it to Chinese hackers. All the company’s product lines were affected including Anthem Blue Cross, Anthem Blue Cross and Blue Shield, and others. Anthem has 37.5 million members enrolled in its affiliated health plans and serves 68.5 million people through all its subsidiary businesses, which includes Medicaid. The CEO Joseph Swedish wrote to its members "I want to personally apologize to each of you for what has happened, as I know you expect us to protect your information. We will continue to do everything in our power to make our systems and security …show more content…

In my research, I found that most health organizations like Anthem have been slower than other organizations such as financial ones to implement necessary technical safeguards like keeping personal information in separate databases that can be closed off in an attack. The more sensitive information needs to be protected in a way that it cannot be broken. Anthem's internal database was not secure, so I feel if they had more security measures in place at the time through encryption, firewalls, an intrusion detection system, and user authentication this might have given them better protection and controlled fraudulent access to the

Open Document