Anthem Health Plans of Kentucky, Incorporated Data Breach
Anthem Kentucky Portable Device Theft Exposes 537 Members
What happened in the Anthem Health Plans of Kentucky, Incorporated data breach?
The Anthem Health Plans of Kentucky, Incorporated data breach was reported on September 29, 2022 and affected 537 individuals. The breach type was Theft involving Other Portable Electronic Device. This breach occurred in Indiana. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Anthem Health Plans of Kentucky, Incorporated Breach Details
Anthem Health Plans of Kentucky Data Breach Report
Incident Overview
Antherm Health Plans of Kentucky, Incorporated reported a data breach affecting 537 individuals on September 29, 2022. The breach resulted from the theft of a portable electronic device containing protected health information (PHI). This incident represents a significant security failure in the handling of sensitive member data and highlights the ongoing risks associated with mobile device management in healthcare organizations. The theft occurred at an unspecified location classified as "Other Portable Electronic Device," indicating the compromised device was likely a laptop, tablet, or similar mobile computing equipment that was not adequately secured.
Discovery and Response Timeline
While specific details regarding the exact discovery date are not provided in the breach submission, Anthem Health Plans of Kentucky initiated an investigation following the theft. The organization's response included a comprehensive review of the device's contents and the scope of potentially exposed information. The breach was formally reported to the Department of Health and Human Services (HHS) on September 29, 2022, meeting the HIPAA Breach Notification Rule requirement to notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery of a breach. Anthem's notification process would have included direct communication to all 537 affected individuals regarding the nature of the breach, the types of information compromised, and recommended protective measures.
Breach Mechanism and Technical Context
The theft of a portable electronic device represents a common but preventable breach vector in healthcare settings. Portable devices such as laptops, tablets, and external storage drives are frequently targeted by thieves due to their high resale value and the valuable data they often contain. Unlike network-based breaches that may involve sophisticated hacking techniques, device theft typically occurs through physical security failures—such as devices left unattended in vehicles, public spaces, or unsecured facilities. The fact that this device contained unencrypted or inadequately protected PHI suggests potential gaps in Anthem's data protection protocols, including possible failures in device encryption, access controls, or data minimization practices. HIPAA Security Rule requirements mandate that covered entities implement appropriate safeguards including encryption of data at rest and in transit, yet portable device theft remains a leading cause of healthcare data breaches.
Organizational Context
Antherm Health Plans of Kentucky, Incorporated is a health insurance company operating in the state of Indiana (as indicated in the breach report metadata), though the entity name suggests primary operations in Kentucky. As a health plan, Anthem maintains extensive databases of member information including enrollment records, claims data, and clinical information. Health insurance companies are significant repositories of PHI due to their role in processing healthcare claims and maintaining member eligibility records. The involvement of a business associate in this breach indicates that the compromised device may have been used by a third-party vendor or contractor working on behalf of Anthem, expanding the potential scope of responsibility and highlighting the importance of vendor management and contractual security requirements under HIPAA.
Impact on Affected Individuals
The breach affected 537 individuals whose personal health information was potentially accessed through the stolen portable device. While the specific data elements exposed are not detailed in the breach submission, typical information maintained by health insurance companies includes names, addresses, phone numbers, email addresses, dates of birth, Social Security numbers, member identification numbers, insurance policy information, and claims history. In some cases, clinical information such as diagnoses, treatment details, and prescription information may also be stored on devices used by insurance company employees. The notification to affected individuals, required under HIPAA, would have specified the exact categories of information compromised and provided guidance on protective measures such as credit monitoring and fraud alert placement.
Patient Risks and Protective Measures
Individuals affected by this breach face several potential risks. The exposure of Social Security numbers combined with names and dates of birth creates significant identity theft risk, as this information is commonly used for fraudulent account creation and financial exploitation. The compromise of insurance policy information and claims history could enable fraudulent claims submission or insurance fraud. Additionally, the exposure of health information could lead to discrimination or privacy violations if the data is misused. Anthem would have been required to offer affected individuals credit monitoring services for a period of time (typically 12-24 months) at no cost, as is standard practice following breaches involving financial identifiers. The organization should also have provided clear instructions for placing fraud alerts and credit freezes with the major credit reporting bureaus.
Industry Context and HIPAA Implications
Portable device theft remains one of the most frequently reported causes of healthcare data breaches. According to HHS breach notification data, device theft accounts for a significant percentage of breaches affecting fewer than 500 individuals, though it can impact larger populations when devices contain aggregated data. The HIPAA Security Rule requires covered entities to implement administrative, physical, and technical safeguards appropriate to the size and complexity of the organization and the nature of the data maintained. Specific requirements include device and media controls, encryption standards, and access controls. This breach demonstrates the importance of implementing mandatory encryption on all portable devices containing PHI, restricting the amount of data stored on mobile devices through data minimization practices, and establishing clear policies regarding device security and accountability. The involvement of a business associate underscores the requirement that covered entities ensure their business associates maintain equivalent security standards through contractual Business Associate Agreements (BAAs) that include specific security and breach notification obligations.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Anthem Health Plans of Kentucky, Incorporated Breach
Place a fraud alert with all three major credit reporting bureaus (Equifax, Experian, TransUnion) immediately and consider placing a credit freeze to prevent unauthorized account opening. Fraud alerts are free and last one year (seven years for identity theft victims).
Monitor credit reports closely for the next 12-24 months by obtaining free annual credit reports at annualcreditreport.com and reviewing them for unauthorized accounts or inquiries. Consider enrolling in the complimentary credit monitoring service offered by Anthem following this breach.
Review explanation of benefits (EOB) statements and insurance claims for accuracy, and contact Anthem immediately if you identify any claims you did not authorize or recognize. Report suspected fraudulent claims to both Anthem and your healthcare providers.
Change passwords for any online accounts associated with your health insurance, particularly if you use the same password across multiple accounts. Enable multi-factor authentication on insurance company portals and other sensitive accounts.
Monitor financial accounts and credit card statements for unauthorized transactions, and consider placing alerts with your financial institutions. If you discover fraudulent activity, report it immediately to your bank and file a report with the Federal Trade Commission at IdentityTheft.gov.
Document all communications with Anthem regarding this breach, including notification letters and any credit monitoring enrollment confirmations. Keep records of any identity theft or fraud incidents that may result from this breach for potential insurance claims or legal action.
Consider placing a police report if you become a victim of identity theft or fraud, as this documentation may be necessary for credit dispute processes and potential recovery efforts.
Stay alert for phishing emails or calls claiming to be from Anthem or healthcare providers requesting personal information. Anthem will not request sensitive information via unsolicited email or phone calls.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Indiana Breaches
Search all breaches reported in Indiana
Active Lawsuit: Anthem Data Breach Settlement
The Anthem data breach of 2015 resulted in a $115 million settlement — one of the largest healthcare breach settlements in history.
Check your eligibility