01Summary
Disclosed in March 2015, the Premera breach involved attackers who had maintained access to the company's network since May 2014. The attackers accessed a wide range of sensitive data including member names, addresses, dates of birth, Social Security numbers, bank account information, and clinical health records. The breach was discovered in January 2015 but took nearly two months to publicly disclose. Security researchers and media reports suggested the attack bore hallmarks of state-sponsored hacking activity, potentially linked to China-based threat actors. The breach was particularly significant because it exposed intimate health information in addition to financial data.
02Background
Premera Blue Cross is a nonprofit health insurance company serving the Pacific Northwest. The healthcare industry had become a prime target for cyberattacks due to the wealth of sensitive personal and medical data held by insurers.
03Key revelations
- 01State-sponsored actors were targeting US healthcare insurers for espionage.
- 02The breach went undetected for nearly 10 months.
- 0311 million individuals had their medical and financial data exposed.
04Technical analysis
The attackers used spear-phishing emails to gain initial access to Premera's network, then moved laterally to access databases containing member records. The prolonged access period (10 months) indicated sophisticated stealth capabilities.
- Attack vector
- Spear-phishing emails
- Attack method
- Network intrusion and data exfiltration
- Initial access
- Spear-phishing
- Lateral movement
- Internal network traversal
MITRE ATT&CK techniques
- T1566.001
05Threat actor
The attack was attributed to a suspected state-sponsored actor, though the specific group was not publicly named. The sophistication and duration of the attack suggested an advanced persistent threat (APT) group with significant resources.
Aliases
- Suspected Chinese APT
Attribution sources
- Media Reports
- Security Researchers
06Victims and impact
Countries affected
- United States
07Data exposed
Data types
- PII
- Names
- SSN
- Bank Account Info
- Medical Records
- Clinical Data
Notable documents
- Premera breach notification letters
08Financial damage
Legal settlements, regulatory fines, and remediation costs in the hundreds of millions.
09Timeline
- 2014-05-05Attackers gain initial access to Premera network.
- 2015-01-29Breach discovered by Premera security team.
- 2015-03-17Premera publicly discloses the breach affecting 11M customers.
10Reaction and fallout
Public reaction
Significant alarm about the security of healthcare data and the length of time the breach went undetected.
Political impact
The breach contributed to increased regulatory scrutiny of healthcare cybersecurity under HIPAA.
Geopolitical consequences
The suspected state-sponsored nature of the attack highlighted the value of health data as an intelligence target.
11Legal
Premera faced multiple class-action lawsuits and regulatory fines.
Civil lawsuits
- Multiple class-action lawsuits
12Aftermath
Policy changes
- Increased HIPAA enforcement and penalties for data breaches.
Regulatory changes
- Stricter requirements for healthcare data protection under HIPAA Omnibus Rule.
Security improvements
- Enhanced network monitoring and threat detection in healthcare sector.
13Significance and legacy
Significance
The Premera breach was one of the largest healthcare data breaches in US history and demonstrated the vulnerability of health insurers to state-sponsored attacks.
Legacy
The incident underscored the need for stronger cybersecurity in the healthcare industry and the growing threat of nation-state attacks on medical data.
14Disclosure and media
- Authentication
- Premera disclosure and media reporting
Publishing organisations
- Premera Blue Cross
16Field notes
- 01The attackers had access to Premera's systems for nearly 10 months before detection.
- 02Premera was the second major US health insurer breached in 2015, following Anthem's 80M record breach.
17Resolution
Premera notified affected members, offered credit monitoring, and enhanced security measures.
18Sources
Official documents
- Premera breach notification to members
References
- [1]Premera official disclosure (2015)
- [2]Media reports (Reuters, The Seattle Times)









