Anthem Health Insurance Hacked: Up to 80 Million Customers Affected

Page 2 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.

vi edit

Elite Member
Super Moderator
Oct 28, 1999
62,403
8,199
126
The next to last time mine was hacked, it was used in Myrtle Beach. The cops got me pics, useless, and told me they get 30 new reports of card theft a day.

The last time. it was used in Alabama. The cop wouldn't even take a report. Said to call my bank.

I'm just surprised that with as much headache as this causes the CC companies, they aren't taking some justice in their own hands. Get a private security firm to start pulling that info and publicly shaming these guys scamming your cards and making your life a pain in the ass.
 

balloonshark

Diamond Member
Jun 5, 2008
6,402
2,839
136
25% executive pay cuts when a breach happens. Mandatory jail sentences when a company covers up a breach. That sounds like a good start to fixing the problems.
 

unokitty

Diamond Member
Jan 5, 2012
3,346
1
0

http://www.usatoday.com/story/tech/2015/02/04/health-care-anthem-hacked/22900925/

Here is a website you can go to:
http://www.anthemfacts.com/

I think it is time for the federal government to mandate serious financial penalties for these big data breaches.
Anthem Blue Cross of California, a WellPoint subsidiary, is a company under attack: it paid a $1 million fine and reinstated over 2,000 customers the state of California said had been improperly dropped from coverage after they became ill, in 2009;3 it faced congressional scrutiny over hefty premium increases in March of 2010,4 and it was called by the California Insurance Commissioner, also in March, to answer charges it violated the law over 700 times. Controversy over WellPoint's practices increased when filings with the Securities and Exchange Commission showed that top executive pay shot up as much as 75 percent in 2009. For example, WellPoint gave CEO Angela Braly a pay increase of 51 percent, bringing her total compensation to $13.1 million...

WellPoint and its subsidiaries gave $4.3 million in the four-year study period 2005–2008. The company gave 42 percent of its total in California ($1.8 million). Almost all of that came from Anthem and Anthem Blue Cross. That money helped finance the California Republican Party ($754,700), the California Democratic Party ($225,000), and Taxpayers for Fair Elections ($195,000)—a ballot measure committee that successfully fought off an attempt to introduce public funding into California campaigns and limit campaign contributions in 2006—as well as many candidates..
Anthem, and the executives that run it, don't care what you think. They pay enough money to politicians and lobbyist that they don't have to care.

The security of your information isn't important to them. They don't care. They don't have to care.

Neither do the politicians care what you think. If your information gets stolen, that's neither Anthem's problem nor is it a politician's problem.

In fact, for the politicians its an opportunity to get even more campaign contributions from Anthem...

Uno
 
Last edited:

maddogchen

Diamond Member
Feb 17, 2004
8,905
2
76
There is a billboard sign I pass on the way to work that says

"it's not a matter of if you will get hacked but when"

seems so true these days
 

holden j caufield

Diamond Member
Dec 30, 1999
6,324
10
81
Is Anthem the 2nd largest in the healthcare insurance field and they did not encrypt this info. I'm no expert but I thought the healthcare field had to follow certain security standards like hipaa or pci compliance.

I still can't believe they don't encrypt that. Did this take at their facilities or where they might be colocated at something like Level 3 or akamai
 

Demo24

Diamond Member
Aug 5, 2004
8,357
9
81
Is Anthem the 2nd largest in the healthcare insurance field and they did not encrypt this info. I'm no expert but I thought the healthcare field had to follow certain security standards like hipaa or pci compliance.

I still can't believe they don't encrypt that. Did this take at their facilities or where they might be colocated at something like Level 3 or akamai


They would have to follow HIPAA (not sure about PCI, probably for CC), but there is nothing in that law that states data must be encrypted. It's somewhat vague about such things, but the takeaway is that as long as you have decent password protection measures in place you are 'in compliance'. You have to 'make a best effort' in such things.

They should probably update the law.
 

JEDI

Lifer
Sep 25, 2001
30,160
3,302
126
"Anyone who has been impacted by this breach will receive written communication from Anthem in the coming weeks."

so it's 80m people in 14 states.
interesting.. wonder why this database had data for only 14 states?
 

highland145

Lifer
Oct 12, 2009
43,551
5,960
136
"Anyone who has been impacted by this breach will receive written communication from Anthem in the coming weeks."

so it's 80m people in 14 states.
interesting.. wonder why this database had data for only 14 states?
Windfall for the USPS.:thumbsup:
 

WackyDan

Diamond Member
Jan 26, 2004
4,794
68
91
"Safeguarding your personal, financial and medical information is one of our top priorities, and because of that, we have state-of-the-art information security systems to protect your data. "

Riiiiight... IF that was the case, we wouldn't be worrying about the data breach you just had. You fuckers probably spent a boatload of money on the network boundary, and endpoint, but probably spent jack all on actual database security which is a completely different thing.... and probably more value these days than traditional security practices.
 

WackyDan

Diamond Member
Jan 26, 2004
4,794
68
91
I love how not only did they get SSN#, names, addresses, etc, but also income.... I can understand why they have the associated income as many of the employers they carry are actually self insurers like my company - They only use Anthem as an administrator essentially.

I still don't understand why my income though is over all important to record on the part of the health insurer.
 

Kneedragger

Golden Member
Feb 18, 2013
1,192
45
91
"Anyone who has been impacted by this breach will receive written communication from Anthem in the coming weeks."

so it's 80m people in 14 states.
interesting.. wonder why this database had data for only 14 states?

My wife received an email this morning from Anthem.
 

dpodblood

Diamond Member
May 20, 2010
4,020
1
81
They would have to follow HIPAA (not sure about PCI, probably for CC), but there is nothing in that law that states data must be encrypted. It's somewhat vague about such things, but the takeaway is that as long as you have decent password protection measures in place you are 'in compliance'. You have to 'make a best effort' in such things.

They should probably update the law.

Data would only need to be encrypted if it were stored on portable media. For data stored in a database on their internal network that wouldn't be necessary by law, and it would actually be very rare for a company to do so. Plus if hackers have made their way inside your network chances are they would be able to obtain the encryption keys and decrypt the data anyway.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |