5 HIPAA Lessons From the Anthem Cyber Attack

Summary:

Another major hack has come to light. Anthem, Inc. was the victim of a cyber attack. They reported that no patient health records have been compromised, but they think Social Security Numbers, addresses, and policy numbers were revealed. This is a nightmare for everyone affected because Social Security Numbers are worth a lot more than […]

Another major hack has come to light. Anthem, Inc. was the victim of a cyber attack. They reported that no patient health records have been compromised, but they think Social Security Numbers, addresses, and policy numbers were revealed.

This is a nightmare for everyone affected because Social Security Numbers are worth a lot more than some credit cards.1 A credit card can be shut down pretty quickly with minimal damage. A compromised Social Security Number opens the door to even more possibilities: fraudulent tax returns, loans, credit cards, etc.

What are the HIPAA lessons we can learn from this attack?

  1. Security Audit – Have you done your Risk Assessment that is required under HIPAA? If you have, when was the last time you updated it? If it’s been more than a year, it’s a good idea to revisit it now. Performing a Risk Assessment makes good business sense for all businesses, not just carriers.
  2. Encryption – Are you encrypting all information stored or transmitted from your devices? The information that was stolen from Anthem wasn’t encrypted. Anthem spokeswoman Kristin Binns told The Wall Street Journal that the company encrypts personal data when it’s moved in or out of the database but not when it’s stored, 2 a practice she said is common in the industry. Make sure you are encrypting that data in all phases – transit, rest and storage.
  3. Firewalls – This can be a hardware device, software configuration, or a combination of both. You will want to block all traffic, and then whitelist connections as you need them. This can help keep hackers out of your systems.
  4. Passwords – Have you recently required password changes for all computer systems? Are you requiring strong passwords? This means at least 8 characters, capitalizations, numbers, and special characters if your system supports this. Weak passwords are an open invitation to hackers.
  5. Training Employees – We don’t know any details on how the hackers were able to access the databases, but make sure your employees know your policies on protecting data in your company or practice.

These steps are not foolproof but can make you less of a target, and make it a little harder for a hacker to get into your systems. Why would a hacker mess with you when there are easy pickin’s elsewhere?

What have the folks at Anthem done properly in dealing with this Breach?

  1. Notify Law Enforcement – If you discover a Breach, your first step is to work with your Security Officer to determine the extent of the Breach. In the case of the Anthem Breach, they contacted the FBI for assistance with this case.
  2. Internal Security Audit – You will want to figure out how you were hacked. Anthem is working with a major IT firm to harden their systems and find out how this happened.
  3. Notify the Public – A Breach of over 500 individuals’ information requires that you notify local media outlets with information on what has happened and how to contact you. Then post the information on a conspicuous place on your website. Anthem issued a press release, and set-up a website with all the information they know about the Breach.
  4. Contact Clients/Patients – You are required to contact all clients and patients that have had their information compromised. Anthem is in the process of determining the extent of the Breaches. They have stated they will be directly contacting those whose information has been compromised.

Anthem is to be commended for the speedy actions they have taken. What remains to be seen is how their systems were compromised. Were they lax in their cybersecurity, was it a poor policy, or will we learn there were software issues? This Breach is a reminder to us all too frequently review our Security Policies and Procedures, and make sure our systems are as secure as possible.

 

 

  1. http://fortune.com/2015/02/05/why-health-hacks-are-worse-than-credit-card-hacks/
  2. http://www.wsj.com/articles/investigators-eye-china-in-anthem-hack-1423167560

Sharing is caring!

Looking for a Business Associate Agreement?

Download our free template to get started on your path toward HIPAA compliance.

Download Now

Want to stay informed?

Join our community, stay ahead of the curve on HIPAA compliance and receive free expert guidance.

Related Posts

HHS’ Office for Civil Rights Settles Ransomware Investigation with Health Plan

HHS’ Office for Civil Rights Settles Ransomware Investigation with Health Plan

The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) announced a $450,000 settlement with Spencer Gifts LLC Flexible Benefits and Welfare Benefit Plans. Triggered by a 2021 ransomware attack that compromised the electronic Protected Health Information (ePHI) of over 10,000 individuals, the investigation revealed systemic failures to conduct accurate risk analyses and implement proper policies and procedures. This case serves as a massive wake-up call. HIPAA compliance extends far beyond traditional healthcare settings; it applies to any organization managing employer-sponsored group health plans, including self-funded and self-insured arrangements.

Why do we need to test our Disaster Recovery Plan every year?

Why do we need to test our Disaster Recovery Plan every year?

Even if your internal software and servers remain perfectly static, the infrastructure, vendor updates, and cyber threats around them are constantly shifting. Waiting 2 or 3 years to test your backup systems leaves you vulnerable. This post breaks down the four external factors that degrade an untested playbook, explores HIPAA compliance mandates under NIST SP 800-66, and provides a granular, step-by-step example of what a compliant disaster recovery blueprint actually looks like.

How to Maintain HIPAA Compliance in Public Cloud Environments

How to Maintain HIPAA Compliance in Public Cloud Environments

Storing ePHI in the public cloud offers scalability but requires a strict “Shared Responsibility” approach. To remain HIPAA compliant, organizations must go beyond basic Business Associate Agreements (BAAs). The implementation of AES-256 encryption, multi-factor authentication (MFA), and microsegmentation are now required. This guide outlines the essential steps to securing your cloud infrastructure while meeting the latest HHS and OCR standards.

Save & Share Cart
Your Shopping Cart will be saved and you'll be given a link. You, or anyone with the link, can use it to retrieve your Cart at any time.
Back Save & Share Cart
Your Shopping Cart will be saved with Product pictures and information, and Cart Totals. Then send it to yourself, or a friend, with a link to retrieve it at any time.
Your cart email sent successfully :)