Code Security

How the Anthem Data Breach Started With One Phishing Email

Amartya | CodeAnt AI Code Review Platform
Sonali Sood

Founding GTM, CodeAnt AI

In February 2015, Anthem disclosed that attackers had taken personal data on 78.8 million people from its systems. It was the largest health data breach in US history until Change Healthcare passed it in 2024.

The attack began almost a year earlier with a spear-phishing email sent to an employee at an Anthem subsidiary. From there, the attackers spent months working their way to the company's enterprise data warehouse.

The Anthem data breach is more than a decade old, and it still reads like a current incident report. The entry point, the missing controls and the gaps OCR cited are the same ones behind breaches in 2025 and 2026.

This teardown walks the timeline, the chain, what regulators found and how to test for the same path today.

What CodeAnt AI solves here: CodeAnt AI tests what a compromised employee identity can actually reach, from the first login through apps, APIs and cloud to the data stores behind them. It proves whether one phished account leads to member records, with a working proof of exploit for each high or critical finding.

What Happened in the Anthem Data Breach

The timeline below draws on the HHS Office for Civil Rights settlement announcement, state attorney general settlements and the 2019 federal indictment.

Date

What happened

February 18, 2014

The earliest date OCR ties to attacker access, after a spear-phishing email lands at an Anthem subsidiary.

2014

The attackers move through Anthem's network toward its enterprise data warehouse.

December 2, 2014 to January 27, 2015

Member data is taken from the warehouse.

January 29, 2015

Anthem discovers the intrusion.

February 4, 2015

Anthem discloses the breach publicly.

March 13, 2015

Anthem files its breach report with OCR.

2017

Anthem agrees to a $115 million class action settlement.

October 15, 2018

Anthem agrees to a record $16 million HIPAA settlement with OCR.

May 2019

A federal grand jury indicts a Chinese national and an unnamed co-defendant over the intrusion.

September 30, 2020

Anthem settles with a multistate coalition of attorneys general for $39.5 million.

Close to a year passed between first access and discovery. For most of that time, the attackers were operating with valid access inside the network.

What Data Was Exposed

According to the New York attorney general, the attackers harvested these fields from Anthem's data warehouse:

  • Identity data: Names, dates of birth and Social Security numbers.

  • Contact data: Home addresses, email addresses and phone numbers.

  • Plan and employment data: Health care identification numbers and employment information.

Anthem said claims and diagnosis data were not part of what was taken. The identity data alone was enough to fuel years of fraud and phishing aimed at members.

The Attack Chain, Technically

Prosecutors described the attackers' techniques as sophisticated. The chain itself had four ordinary links.

Stage 1. A spear-phishing email to a subsidiary

The attackers sent tailored emails with embedded links to employees of an Anthem subsidiary. According to OCR, at least one employee responded, and that opened the door. Subsidiaries are a common target for this reason. They often run with lighter security oversight while still holding trusted connections into the parent company's network.

Stage 2. Malware and harvested credentials

The indictment says the group installed malware on Anthem's systems once inside. The foothold gave them a place to harvest credentials and learn the network. Every credential collected at this stage widened the set of systems the attackers could reach while looking like normal users.

Stage 3. Months of movement toward the data warehouse

The attackers worked their way from the subsidiary foothold to Anthem's enterprise data warehouse, the central store holding member records. That took most of 2014. OCR later found Anthem lacked adequate minimum access controls. Put plainly, too many paths led to the most sensitive data store in the company.

Stage 4. Bulk queries and exfiltration

Between December 2014 and late January 2015, the attackers queried the warehouse and moved the results out. A warehouse built to answer big questions quickly answered theirs too. Anthem said the activity was caught when an employee noticed a database query running under his own credentials that he had not started. Its most effective intrusion detection system turned out to be one administrator who knew his own query history.

What OCR Found

OCR's investigation went beyond the phishing email. It listed four failures that let the attack succeed, starting as early as February 18, 2014.

  • No enterprise-wide risk analysis: Anthem had not assessed the risks to ePHI across its whole environment.

  • Insufficient activity review: Procedures to regularly review information system activity were not adequate.

  • Weak incident detection and response: Anthem failed to identify and respond to suspected or known security incidents.

  • Inadequate access controls: Minimum access controls did not stop the attackers from reaching sensitive ePHI.

Those four findings map almost line for line onto what OCR cites today. Our comparison of HIPAA risk assessments and penetration testing explains why a paper risk analysis does not prove what an attacker can reach.

Why a 2015 Breach Still Matters in 2026

The entry points have shifted over the decade. The chain after the first login has barely moved.

Attribute

Anthem (2014 to 2015)

Change Healthcare (2024)

Entry point

Spear-phishing email to a subsidiary employee

Stolen credentials on a remote access portal

Missing control

Access controls and activity review

Multi-factor authentication on the portal

Time inside before detection

Close to a year

Nine days before ransomware

What was reached

Enterprise data warehouse

Core systems and patient data

People affected

78.8 million

About 192.7 million

Both attacks started with a valid identity and grew because nothing limited where that identity could go. Our teardown of the Change Healthcare remote-access attack walks the newer chain in detail.

Enforcement in 2026 still targets the same basics. In September 2026, OCR settled with Ambry Genetics for $700,000 over a breach that also started with a phishing email, with findings centered on risk analysis and access control.

What a Real Test Against This Chain Looks Like

Phishing resistance is partly a people problem. What a phished identity can reach afterward is a testing problem, and that is where this breach grew from one inbox to 78.8 million records.

Chain link

What the test checks

Evidence it produces

Phished identity

Start from a standard employee account, as the attacker did

A realistic assumed-breach starting point

Subsidiary trust

Whether subsidiary accounts and systems reach parent company resources

Every cross-entity path that should not exist

Access to the data store

Whether that identity can query member data through apps, APIs or cloud consoles

Records reachable, with sample evidence

Bulk extraction

Whether large queries or exports are possible and whether anything flags them

Proof of bulk access and time to detect

Privileged accounts

Whether administrator and service credentials can be reused elsewhere

The escalation path from one account to many

Our guide to IDOR and broken access control covers how one account ends up reading records it should never see. Our breakdown of black box, white box and gray box testing covers the assumed-breach approach.

Lessons for Health Plans and Payers

The Anthem data breach left lessons that every health plan can apply today.

  • Test from the inside out: Assume one employee will click. Measure what their account can reach, and shrink it.

  • Treat subsidiaries as external: Trust between entities should be explicit, limited and tested.

  • Guard the data warehouse: Central data stores need query-level access control and alerts on unusual volume.

  • Watch privileged credentials: An administrator account used from a new place or for a new query pattern should trigger review.

  • Keep the risk analysis current: OCR's first finding was the missing enterprise-wide risk analysis. It is still the first thing investigators ask for.

The same patterns run through the rest of the industry. Our guides to how insurers get breached through portals, APIs and vendors and how healthcare data breaches happen cover the wider picture.

The Legal and Regulatory Fallout

Anthem paid out in three separate settlements, plus the costs of notification and credit monitoring.

Settlement

Amount

Year

Consumer class action

$115 million

2017

HHS Office for Civil Rights (HIPAA)

$16 million

2018

Multistate attorneys general

$39.5 million

2020

The OCR payment was the largest HIPAA settlement at the time, well above the previous record of $5.55 million. Anthem also agreed to a corrective action plan with OCR and to third-party security assessments under the state settlement.

How CodeAnt Would Have Caught This

The Anthem intrusion happened in 2014, and its internal details are only partly public. So we won't claim CodeAnt would have stopped it.

The gap it exploited, one identity reaching far more than it should, is what CodeAnt's testing is built to measure.

  • Gray box testing from a compromised identity: Agents authenticate as a standard session and chain what it can reach, including IDOR, broken object level authorization and privilege escalation paths, toward member data.

  • Code-aware access control testing: White box analysis reads the code behind APIs and internal services to find endpoints that return data without checking who is asking.

  • Proof, with evidence: Each high or critical finding ships with a working proof of exploit, so the question of whether one account can reach the warehouse has a demonstrated answer.

  • Continuous coverage: Testing runs as systems change, so a new integration or data store is tested when it appears.

The walkthrough of how AI penetration testing traces a data leak shows a full chain end to end.

The Fix

The Anthem data breach started with one email and succeeded because nothing limited where the resulting access could go. A decade later, the same chain keeps working against organizations that test the front door and never test the hallway. Assume someone will click. Then prove what their account can reach, and cut it down.

Run a free black box scan on one URL to see your exposed surface, then book a walkthrough to see gray box testing chained through to a proven data leak. For the compliance side, start with our guide to HIPAA penetration testing requirements.

FAQs

What happened in the Anthem data breach?

How did hackers get into Anthem?

How many people were affected by the Anthem breach?

How much did Anthem pay for the data breach?

Who was behind the Anthem data breach?

Start Your 14-Day Free Trial

AI code reviews, security and quality trusted by modern engineering teams.

Table of Content
No headings found on page

Ship clean & secure code faster

Get Pentest Report

NO CC REQUIRED