In February 2015, health insurer Anthem said its database had been compromised, exposing personal information for 78.8 million people, including 60 million to 70 million of its current and former customers and employees. Two years later, much of how it happened, who did it, and what consequences Anthem will face remain unanswered. From a report: Anthem has not disclosed the value of its cyber insurance policy, which defrays some of the costs. The hackers were most likely working on behalf of a foreign government. Many security experts believe it was China, but that has not been proven yet. The FBI would not comment on the pending investigation. It’s unclear if Anthem will face a federal penalty. It’s by far the largest health care data breach, and the Department of Health and Human Services has imposed fines in the past. We don’t know for sure that Anthem was fully protected from this type of attack, and a separate federal agency that had a contract with Anthem previously said the insurer did not have controls in place “to prevent rogue devices…from connecting to its networks.” Class-action lawsuits are still pending, and fact-finding discovery ended in December. Anthem could escape big damages if people can’t show concrete harm.
Read more of this story at Slashdot.