Penalty Amount
$150,000
Anthem Blue Cross printed Social Security numbers on mailed letters, exposing the personal information of over 33,000 Medicare subscribers. The settlement requires the company to improve data security measures, provide employee training, and pay $150,000. This action aims to prevent future privacy violations.
Anthem must pay $150,000, implement new technical safeguards for data management, restrict employee access to Social Security numbers, and provide enhanced data security training for all associates.
In-house legal teams should scrutinize all agreements involving customer communications and data processing, particularly with mailing service providers, third-party logistics vendors, and any entities handling personally identifiable information (PII). Key clauses to review include data security standards (e.g., encryption, redaction, and access controls for physical mail), mandatory employee training on data handling, data retention and disposal policies, and breach notification procedures. Given the exposure of Social Security numbers via mailed letters, contracts must explicitly require encryption or redaction of sensitive PII in physical correspondence, regular security audits, and immediate reporting of data mishandling. Consider adding indemnification provisions for privacy violations and requiring vendors to comply with frameworks like NIST or ISO 27001. Updates may also be needed in customer-facing agreements to clarify data handling practices and in employee contracts to reinforce confidentiality obligations.
Entity
Blue Cross of California
Also known as: Anthem
Industry
HealthcareOfficial Press Release
Stipulation Redacted 0
https://oag.ca.gov/system/files/attachments/press_releases/Stipulation_Redacted_0.pdf
Complaint Redacted 0
https://oag.ca.gov/system/files/attachments/press_releases/Complaint_Redacted_0.pdf
Signed final judgement 0
https://oag.ca.gov/system/files/attachments/press_releases/Signed%20final%20judgement_0.pdf
California Attorney General Enforcement Page
https://oag.ca.gov/privacy/privacy-enforcement-actions
A coalition of 12 state attorneys general, led by Colorado AG Phil Weiser, obtained a temporary restraining order from a federal court in California to halt the proposed $110 billion merger of Warner Bros. Discovery, Inc. by Paramount Skydance Corporation. The lawsuit alleges the merger violates Section 7 of the Clayton Act by substantially lessening competition in film distribution, anticipated blockbuster film distribution, and licensing cable TV channels.
The California Privacy Protection Agency (CalPrivacy) joined a coalition of 18 Attorneys General and state agencies in opposing the proposed SECURE Data Act, a federal privacy bill that would preempt stronger state privacy laws like the CCPA. The coalition argues the bill would weaken consumer privacy protections, limit enforcement remedies, and undermine California's Delete Request and Opt-out Platform (DROP).
$12.8M
California Attorney General Rob Bonta, along with multiple district attorneys and the California Privacy Protection Agency, announced a $12.75 million settlement with General Motors for illegally selling hundreds of thousands of Californians' location and driving data to data brokers Verisk and LexisNexis without notice or consent. The settlement includes the largest CCPA penalty to date, a five-year ban on selling driving data to consumer reporting agencies, and requirements to delete retained data and implement a robust privacy program.
The California Privacy Protection Agency Board voted to support two bills (AB 1542 and SB 1106) and took a 'support if amended' position on a third bill (AB 883). These bills aim to strengthen privacy protections by expanding sensitive data protections, improving deletion rights under the Delete Act, and providing expedited deletion for elected officials and judges.
The California Privacy Protection Agency sent a letter to Congress opposing the SECURE Data Act, a federal bill that would preempt state privacy laws like the CCPA and Delete Act. The letter argues the bill would eliminate rights for 40 million Californians, including the DROP platform and opt-out preference signal requirements, and urges Congress to set a floor rather than a ceiling on privacy protections.
California Attorney General Rob Bonta, joined by attorneys general from seven other states, filed a lawsuit to block the $6.2 billion merger between Nexstar Media Group and Tegna Inc. The lawsuit alleges the merger violates Section 7 of the Clayton Act by reducing competition in local TV markets, leading to higher prices, less local news, and job losses.