In late January, Anthem announced that it had been breached, compromising data from 80 million people. It is the largest publicly-disclosed breach of a healthcare company.
Although Anthem’s network was initially believed to be breached in January, Brian Krebs reported that the breach could have started back in April of 2014. Krebs also said the attack included a phishing campaign in May of 2014.
No matter when or how a company discovers a breach (through its own work or a third party like the FBI), it’s important to act quickly in order to limit the damage caused by the attack. Damage control is an important element of information security.
The Healthcare Industry’s Information Security Performance
| Industry | Security Rating |
| Healthcare | 620 |
| Finance | 710 |
| Retail | 660 |
| Utilities | 620 |
| Government | 610 |
As you can see in the table above, the healthcare industry is still behind Finance and Retail. It has the same rating as Utilities, and is just barely ahead of Government. (Healthcare was also struggling in a Bitsight Insights report published last May.) Although our ratings are not predictive, we do believe that poor security performance is an indicator of greater security risk and should be cause for concern.
Watch Bitsight Executive Vice President, Tom Turner, speak about the security performance of the healthcare industry in this CBS Evening News piece.