Breach report
HealthcarePremera Blue Cross
Premera Blue Cross Breach May Have Exposed 11 Million Customers' Medical And Financial Data
Attackers lurked in Premera Blue Cross's systems for eight months before discovery, potentially exposing medical claims, bank details and Social Security numbers for about 11 million members going back more than a decade.
Reported by Forbes
Records exposed
11M
About 11 million people
Scale vs. largest on file
- When
- 2014 (disclosed 2015)
- How they got in
- Targeted intrusion via phishing and malware (suspected state-sponsored)
- Sector
- Healthcare
On March 17, 2015, Seattle-area health insurer Premera Blue Cross disclosed that hackers had gained access to its information systems, potentially exposing data on roughly 11 million people. The affected population included Premera members in Washington and Alaska, members of affiliated brands, and customers of other Blue Cross Blue Shield plans who had received care in Premera's service area. Critics questioned why nearly seven weeks passed between the insurer's discovery of the intrusion and its public announcement.
The initial compromise took place on May 5, 2014, but Premera did not discover it until January 29, 2015, meaning intruders had roughly eight months of access. Investigators and later litigation described phishing emails and malware that let attackers establish a foothold. Security researchers linked the campaign to a China-based espionage group also suspected in the Anthem intrusion disclosed weeks earlier, and both companies described the attacks as highly sophisticated.
The records at risk were unusually broad. Beyond names, birthdates, Social Security numbers and contact details, Premera said the attackers may have accessed bank account information and medical claims data, including clinical information, for some members, with records dating back to 2002. The company said it had no evidence at the time that the data had been removed or misused, and it offered two years of free credit monitoring and identity protection.
The fallout took years to resolve. Premera agreed in 2019 to a $74 million class-action settlement and a separate $10 million settlement with 30 state attorneys general, who alleged the insurer had ignored warnings from auditors about weak security. In 2020 the insurer paid $6.85 million to the U.S. Department of Health and Human Services to settle HIPAA violations, one of the larger penalties the agency had imposed. Plaintiffs also accused Premera of mishandling forensic evidence, a claim the company disputed.
Arriving so soon after Anthem, the Premera breach made clear that health insurers had become prime targets for espionage-motivated hackers who value comprehensive, unchangeable personal data. Regulators cited the case to press insurers on basic controls such as patching, risk assessments and timely detection, and the eight-month gap before discovery became a cautionary example of weak monitoring.