EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/premera-blue-cross-breach-2015
275/430

File EL-0156CriticalResolvedData Breach / Healthcare Data Breach

Premera Blue Cross Data Breach (2015)

Also filed as Premera Health Data Breach · Anthem/Premera Insurance Hacks

Premera Blue Cross suffered a massive data breach affecting 11 million customers. Attackers gained access to the health insurer's IT systems for nearly a year, exfiltrating medical records, financial data, and personally identifiable information. The breach was attributed to a suspected state-sponsored actor.

  • #premera-blue-cross
  • #healthcare
  • #data-breach
  • #pii
  • #medical-records
  • #2015
Notoriety7/10
Event
17 Mar 2015
Disclosed
17 Mar 2015
Target
Premera Blue Cross
Actor
Unknown (State-Sponsored Suspected)
Scale
11.0M people
Status
Resolved

01Summary

Disclosed in March 2015, the Premera breach involved attackers who had maintained access to the company's network since May 2014. The attackers accessed a wide range of sensitive data including member names, addresses, dates of birth, Social Security numbers, bank account information, and clinical health records. The breach was discovered in January 2015 but took nearly two months to publicly disclose. Security researchers and media reports suggested the attack bore hallmarks of state-sponsored hacking activity, potentially linked to China-based threat actors. The breach was particularly significant because it exposed intimate health information in addition to financial data.

02Background

Premera Blue Cross is a nonprofit health insurance company serving the Pacific Northwest. The healthcare industry had become a prime target for cyberattacks due to the wealth of sensitive personal and medical data held by insurers.

03Key revelations

  1. 01State-sponsored actors were targeting US healthcare insurers for espionage.
  2. 02The breach went undetected for nearly 10 months.
  3. 0311 million individuals had their medical and financial data exposed.

04Technical analysis

The attackers used spear-phishing emails to gain initial access to Premera's network, then moved laterally to access databases containing member records. The prolonged access period (10 months) indicated sophisticated stealth capabilities.

Attack vector
Spear-phishing emails
Attack method
Network intrusion and data exfiltration
Initial access
Spear-phishing
Lateral movement
Internal network traversal

MITRE ATT&CK techniques

  • T1566.001

05Threat actor

The attack was attributed to a suspected state-sponsored actor, though the specific group was not publicly named. The sophistication and duration of the attack suggested an advanced persistent threat (APT) group with significant resources.

Aliases

  • Suspected Chinese APT

Attribution sources

  • Media Reports
  • Security Researchers

06Victims and impact

Countries affected

  • United States

07Data exposed

Data types

  • PII
  • Names
  • SSN
  • Bank Account Info
  • Medical Records
  • Clinical Data

Notable documents

  • Premera breach notification letters

08Financial damage

Legal settlements, regulatory fines, and remediation costs in the hundreds of millions.

09Timeline

  1. 2014-05-05Attackers gain initial access to Premera network.
  2. 2015-01-29Breach discovered by Premera security team.
  3. 2015-03-17Premera publicly discloses the breach affecting 11M customers.

10Reaction and fallout

Public reaction

Significant alarm about the security of healthcare data and the length of time the breach went undetected.

Political impact

The breach contributed to increased regulatory scrutiny of healthcare cybersecurity under HIPAA.

Geopolitical consequences

The suspected state-sponsored nature of the attack highlighted the value of health data as an intelligence target.

11Legal

Premera faced multiple class-action lawsuits and regulatory fines.

Civil lawsuits

  • Multiple class-action lawsuits

12Aftermath

Policy changes

  • Increased HIPAA enforcement and penalties for data breaches.

Regulatory changes

  • Stricter requirements for healthcare data protection under HIPAA Omnibus Rule.

Security improvements

  • Enhanced network monitoring and threat detection in healthcare sector.

13Significance and legacy

Significance

The Premera breach was one of the largest healthcare data breaches in US history and demonstrated the vulnerability of health insurers to state-sponsored attacks.

Legacy

The incident underscored the need for stronger cybersecurity in the healthcare industry and the growing threat of nation-state attacks on medical data.

14Disclosure and media

Authentication
Premera disclosure and media reporting

Publishing organisations

  • Premera Blue Cross

15Related files

Related events

  • Anthem breach (2015)

16Field notes

  1. 01The attackers had access to Premera's systems for nearly 10 months before detection.
  2. 02Premera was the second major US health insurer breached in 2015, following Anthem's 80M record breach.

17Resolution

Premera notified affected members, offered credit monitoring, and enhanced security measures.

18Sources

Official documents

  • Premera breach notification to members

References

  1. [1]Premera official disclosure (2015)
  2. [2]Media reports (Reuters, The Seattle Times)
Fact sheetEL-0156

Dates

Event
17 Mar 2015
Started
5 May 2014
Ended
17 Mar 2015
Duration
315 days
Discovered
29 Jan 2015
Disclosed
17 Mar 2015
Ongoing
No

Target

Organisation
Premera Blue Cross (health insurance provider)
Type
Corporation
Sector
Healthcare / Insurance
Country
United States

Actor

Name
Unknown (State-Sponsored Suspected)
Type
Nation-State Actor
Nation-state
Suspected China
Motivation
Intelligence gathering; likely targeting of health records for espionage purposes.
Attribution
Low
Status
Active
Arrested
No
Convicted
No

Data

People
11,000,000
Records
11,000,000
Volume
11 million records
Sensitivity
Top Secret
Published
No
Sold (dark web)
No

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.