← All enforcement actions
HIPAAHealthcare

Anthem Inc.$16M HIPAA fine (2018)

Largest HIPAA settlement in history — 78.8M records breached

Penalty
$16M
Regulator
HHS Office for Civil Rights (OCR)
Jurisdiction
United States
Records affected
78.8M

What happened

A spear-phishing email compromised an Anthem subsidiary, exposing names, DOBs, SSNs, medical IDs, addresses, employment info, and income data for 78.8M individuals. OCR settled with Anthem for $16M plus a corrective action plan — and a separate civil class action settled for ~$115M.

Root cause

What every team should do

  1. Conduct + DOCUMENT a recurring, signed enterprise risk analysis — the #1 OCR audit finding
  2. Enforce phishing-resistant MFA on every account with PHI access (FIDO2/WebAuthn)
  3. Enable SIEM with playbooks for suspected incidents — Security Rule §164.308(a)(6)
  4. Annual workforce phishing simulations + remediation training
Source: HHS OCR press release (Oct 15, 2018).
Would your controls have stopped this?

ComplianceIQ audits your existing policies in 60 seconds and shows you exactly which HIPAA controls you are missing — mapped to enforcement patterns like this one.

Run my HIPAA audit Generate missing policies

Related enforcement actions

Premera Blue Cross
$6.85M
11M-record breach + risk-analysis + access-controls failures