Penalty Amount
$8,690,000
Consumers Affected
78,000,000
California Attorney General Xavier Becerra announced an $8.69 million settlement with health insurer Anthem, Inc. resolving allegations that the company violated state and federal privacy laws by failing to protect patient personal data in a 2014 data breach. The breach, announced in 2015, exposed personal information of 78 million consumers nationwide, including 13.5 million Californians, due to Anthem’s inadequate information security practices. The settlement includes injunctive terms requiring Anthem to overhaul its information security program to address vulnerabilities that enabled the breach.
Anthem must pay $8.69 million in monetary penalties. The settlement also includes injunctive terms requiring Anthem to modify its information security program to remediate vulnerabilities that enabled the 2014 data breach, including addressing deficiencies in access controls, account credential protection, security tool updates, and network activity logging and monitoring.
In-house legal teams at healthcare entities, HIPAA-covered organizations, and companies handling sensitive consumer data should review vendor agreements (including HIPAA Business Associate Agreements), customer contracts, and internal compliance policies. Key clauses to audit include information security program requirements, access controls for sensitive data, account credential protection standards, mandatory security tool update schedules, and network activity logging and monitoring obligations. Teams should also verify that breach notification clauses align with state and federal requirements, and that vendor contracts include audit rights to assess compliance with security standards. Additionally, any existing settlement or consent decree compliance clauses should be updated to reflect injunctive requirements for security program remediation.
Entity
Anthem, Inc.
Also known as: Anthem
Industry
HealthcareOfficial Press Release
https://oag.ca.gov/news/press-releases/attorney-general-becerra-announces-869-million-settlement-against-anthem-inc
People v Anthem Complaint
https://oag.ca.gov/sites/default/files/People%20v%20Anthem%20-%20Complaint.pdf
Anthem FINAL Stipulation
https://oag.ca.gov/sites/default/files/Anthem%20-%20FINAL%20-%20Stipulation.pdf
California Attorney General Enforcement Page
https://oag.ca.gov/privacy/privacy-enforcement-actions
"Anthem, Inc."
"$8.69 million"
"California’s consumer protection laws"
"federal Health Insurance Portability & Accountability Act (HIPAA)"
"2014 data breach"
"numerous deficiencies in basic security, including not limiting access to computers holding sensitive information, not protecting account credentials and passwords from unauthorized use, not updating security tools, and not adequately logging and monitoring network activity to detect malicious activity."
$39.5M
New Jersey Attorney General announced a multi-state settlement with Anthem, Inc. over a 2015 data breach that exposed personal information of over 78 million Americans, including 1.15 million New Jersey residents. Anthem will pay $39.5 million to participating states and implement enhanced cybersecurity measures.
A bipartisan coalition of 33 state attorneys general, led by Minnesota AG Keith Ellison, began trial against Meta Platforms, Inc., alleging the company knowingly designed and deployed harmful features on Facebook and Instagram that drive children and teens to use the platforms compulsively, while falsely assuring parents and the public that its platforms were safe for young users. The states also allege Meta illegally collected personal information from children under 13 without parental consent, violating COPPA. The trial opened before Judge Yvonne Gonzalez Rogers in the U.S. District Court for the Northern District of California, with the states seeking monetary penalties and injunctive relief.
A coalition of 12 state attorneys general, led by Colorado AG Phil Weiser, obtained a temporary restraining order from a federal court in California to halt the proposed $110 billion merger of Warner Bros. Discovery, Inc. by Paramount Skydance Corporation. The lawsuit alleges the merger violates Section 7 of the Clayton Act by substantially lessening competition in film distribution, anticipated blockbuster film distribution, and licensing cable TV channels.
The California Privacy Protection Agency (CalPrivacy) joined a coalition of 18 Attorneys General and state agencies in opposing the proposed SECURE Data Act, a federal privacy bill that would preempt stronger state privacy laws like the CCPA. The coalition argues the bill would weaken consumer privacy protections, limit enforcement remedies, and undermine California's Delete Request and Opt-out Platform (DROP).
A bipartisan coalition of state attorneys general began trial against Meta Platforms, Inc., alleging the company knowingly designed addictive features on Facebook and Instagram that harm children and teens, deceived parents about platform safety, and illegally collected personal information from children under 13 without parental consent in violation of COPPA. The states seek monetary penalties, an injunction to stop unlawful practices, and other relief. The trial is being litigated in the U.S. District Court for the Northern District of California.
$12.8M
California Attorney General Rob Bonta, along with multiple district attorneys and the California Privacy Protection Agency, announced a $12.75 million settlement with General Motors for illegally selling hundreds of thousands of Californians' location and driving data to data brokers Verisk and LexisNexis without notice or consent. The settlement includes the largest CCPA penalty to date, a five-year ban on selling driving data to consumer reporting agencies, and requirements to delete retained data and implement a robust privacy program.