← All enforcement actions
HIPAAHealthcare

Premera Blue Cross$6.85M HIPAA fine (2020)

11M-record breach + risk-analysis + access-controls failures

Penalty
$6.85M
Regulator
HHS OCR
Jurisdiction
United States
Records affected
11M

What happened

An undetected APT compromise from May 2014 to March 2015 exposed ePHI of 11M individuals. OCR's investigation found systemic Security Rule failures: insufficient risk analysis, insufficient risk management, and failures around access controls and audit reviews.

Root cause

What every team should do

  1. Risk analysis must cover ALL systems that create/receive/maintain/transmit ePHI
  2. Centralise + actively review audit logs (Security Rule §164.312(b))
  3. Implement least-privilege + Just-In-Time access for production ePHI systems
Source: HHS OCR press release (Sep 25, 2020).
Would your controls have stopped this?

ComplianceIQ audits your existing policies in 60 seconds and shows you exactly which HIPAA controls you are missing — mapped to enforcement patterns like this one.

Run my HIPAA audit Generate missing policies

Related enforcement actions

Anthem Inc.
$16M
Largest HIPAA settlement in history — 78.8M records breached