In February 2015, Anthem disclosed that attackers had taken personal data on 78.8 million people from its systems. It was the largest health data breach in US history until Change Healthcare passed it in 2024.
The attack began almost a year earlier with a spear-phishing email sent to an employee at an Anthem subsidiary. From there, the attackers spent months working their way to the company's enterprise data warehouse.
The Anthem data breach is more than a decade old, and it still reads like a current incident report. The entry point, the missing controls and the gaps OCR cited are the same ones behind breaches in 2025 and 2026.
This teardown walks the timeline, the chain, what regulators found and how to test for the same path today.
What CodeAnt AI solves here: CodeAnt AI tests what a compromised employee identity can actually reach, from the first login through apps, APIs and cloud to the data stores behind them. It proves whether one phished account leads to member records, with a working proof of exploit for each high or critical finding.
What Happened in the Anthem Data Breach
The timeline below draws on the HHS Office for Civil Rights settlement announcement, state attorney general settlements and the 2019 federal indictment.
Date | What happened |
|---|---|
February 18, 2014 | The earliest date OCR ties to attacker access, after a spear-phishing email lands at an Anthem subsidiary. |
2014 | The attackers move through Anthem's network toward its enterprise data warehouse. |
December 2, 2014 to January 27, 2015 | Member data is taken from the warehouse. |
January 29, 2015 | Anthem discovers the intrusion. |
February 4, 2015 | Anthem discloses the breach publicly. |
March 13, 2015 | Anthem files its breach report with OCR. |
2017 | Anthem agrees to a $115 million class action settlement. |
October 15, 2018 | Anthem agrees to a record $16 million HIPAA settlement with OCR. |
May 2019 | A federal grand jury indicts a Chinese national and an unnamed co-defendant over the intrusion. |
September 30, 2020 | Anthem settles with a multistate coalition of attorneys general for $39.5 million. |
Close to a year passed between first access and discovery. For most of that time, the attackers were operating with valid access inside the network.
What Data Was Exposed
According to the New York attorney general, the attackers harvested these fields from Anthem's data warehouse:
Identity data: Names, dates of birth and Social Security numbers.
Contact data: Home addresses, email addresses and phone numbers.
Plan and employment data: Health care identification numbers and employment information.
Anthem said claims and diagnosis data were not part of what was taken. The identity data alone was enough to fuel years of fraud and phishing aimed at members.
The Attack Chain, Technically
Prosecutors described the attackers' techniques as sophisticated. The chain itself had four ordinary links.
Stage 1. A spear-phishing email to a subsidiary
The attackers sent tailored emails with embedded links to employees of an Anthem subsidiary. According to OCR, at least one employee responded, and that opened the door. Subsidiaries are a common target for this reason. They often run with lighter security oversight while still holding trusted connections into the parent company's network.
Stage 2. Malware and harvested credentials
The indictment says the group installed malware on Anthem's systems once inside. The foothold gave them a place to harvest credentials and learn the network. Every credential collected at this stage widened the set of systems the attackers could reach while looking like normal users.
Stage 3. Months of movement toward the data warehouse
The attackers worked their way from the subsidiary foothold to Anthem's enterprise data warehouse, the central store holding member records. That took most of 2014. OCR later found Anthem lacked adequate minimum access controls. Put plainly, too many paths led to the most sensitive data store in the company.
Stage 4. Bulk queries and exfiltration
Between December 2014 and late January 2015, the attackers queried the warehouse and moved the results out. A warehouse built to answer big questions quickly answered theirs too. Anthem said the activity was caught when an employee noticed a database query running under his own credentials that he had not started. Its most effective intrusion detection system turned out to be one administrator who knew his own query history.
What OCR Found
OCR's investigation went beyond the phishing email. It listed four failures that let the attack succeed, starting as early as February 18, 2014.
No enterprise-wide risk analysis: Anthem had not assessed the risks to ePHI across its whole environment.
Insufficient activity review: Procedures to regularly review information system activity were not adequate.
Weak incident detection and response: Anthem failed to identify and respond to suspected or known security incidents.
Inadequate access controls: Minimum access controls did not stop the attackers from reaching sensitive ePHI.
Those four findings map almost line for line onto what OCR cites today. Our comparison of HIPAA risk assessments and penetration testing explains why a paper risk analysis does not prove what an attacker can reach.
Why a 2015 Breach Still Matters in 2026
The entry points have shifted over the decade. The chain after the first login has barely moved.
Attribute | Anthem (2014 to 2015) | Change Healthcare (2024) |
|---|---|---|
Entry point | Spear-phishing email to a subsidiary employee | Stolen credentials on a remote access portal |
Missing control | Access controls and activity review | Multi-factor authentication on the portal |
Time inside before detection | Close to a year | Nine days before ransomware |
What was reached | Enterprise data warehouse | Core systems and patient data |
People affected | 78.8 million | About 192.7 million |
Both attacks started with a valid identity and grew because nothing limited where that identity could go. Our teardown of the Change Healthcare remote-access attack walks the newer chain in detail.
Enforcement in 2026 still targets the same basics. In September 2026, OCR settled with Ambry Genetics for $700,000 over a breach that also started with a phishing email, with findings centered on risk analysis and access control.
What a Real Test Against This Chain Looks Like
Phishing resistance is partly a people problem. What a phished identity can reach afterward is a testing problem, and that is where this breach grew from one inbox to 78.8 million records.
Chain link | What the test checks | Evidence it produces |
|---|---|---|
Phished identity | Start from a standard employee account, as the attacker did | A realistic assumed-breach starting point |
Subsidiary trust | Whether subsidiary accounts and systems reach parent company resources | Every cross-entity path that should not exist |
Access to the data store | Whether that identity can query member data through apps, APIs or cloud consoles | Records reachable, with sample evidence |
Bulk extraction | Whether large queries or exports are possible and whether anything flags them | Proof of bulk access and time to detect |
Privileged accounts | Whether administrator and service credentials can be reused elsewhere | The escalation path from one account to many |
Our guide to IDOR and broken access control covers how one account ends up reading records it should never see. Our breakdown of black box, white box and gray box testing covers the assumed-breach approach.
Lessons for Health Plans and Payers
The Anthem data breach left lessons that every health plan can apply today.
Test from the inside out: Assume one employee will click. Measure what their account can reach, and shrink it.
Treat subsidiaries as external: Trust between entities should be explicit, limited and tested.
Guard the data warehouse: Central data stores need query-level access control and alerts on unusual volume.
Watch privileged credentials: An administrator account used from a new place or for a new query pattern should trigger review.
Keep the risk analysis current: OCR's first finding was the missing enterprise-wide risk analysis. It is still the first thing investigators ask for.
The same patterns run through the rest of the industry. Our guides to how insurers get breached through portals, APIs and vendors and how healthcare data breaches happen cover the wider picture.
The Legal and Regulatory Fallout
Anthem paid out in three separate settlements, plus the costs of notification and credit monitoring.
Settlement | Amount | Year |
|---|---|---|
Consumer class action | $115 million | 2017 |
HHS Office for Civil Rights (HIPAA) | $16 million | 2018 |
Multistate attorneys general | $39.5 million | 2020 |
The OCR payment was the largest HIPAA settlement at the time, well above the previous record of $5.55 million. Anthem also agreed to a corrective action plan with OCR and to third-party security assessments under the state settlement.
How CodeAnt Would Have Caught This
The Anthem intrusion happened in 2014, and its internal details are only partly public. So we won't claim CodeAnt would have stopped it.
The gap it exploited, one identity reaching far more than it should, is what CodeAnt's testing is built to measure.
Gray box testing from a compromised identity: Agents authenticate as a standard session and chain what it can reach, including IDOR, broken object level authorization and privilege escalation paths, toward member data.
Code-aware access control testing: White box analysis reads the code behind APIs and internal services to find endpoints that return data without checking who is asking.
Proof, with evidence: Each high or critical finding ships with a working proof of exploit, so the question of whether one account can reach the warehouse has a demonstrated answer.
Continuous coverage: Testing runs as systems change, so a new integration or data store is tested when it appears.
The walkthrough of how AI penetration testing traces a data leak shows a full chain end to end.
The Fix
The Anthem data breach started with one email and succeeded because nothing limited where the resulting access could go. A decade later, the same chain keeps working against organizations that test the front door and never test the hallway. Assume someone will click. Then prove what their account can reach, and cut it down.
Run a free black box scan on one URL to see your exposed surface, then book a walkthrough to see gray box testing chained through to a proven data leak. For the compliance side, start with our guide to HIPAA penetration testing requirements.


