Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - The Anthem and Premera Data Breaches Put the Healthcare Industry on Notice: You are a Target
Articles

The Anthem and Premera Data Breaches Put the Healthcare Industry on Notice: You are a Target

ISBuzz TeamBy ISBuzz TeamMarch 31, 2015Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Recent headlines have put the healthcare industry in the spotlight, and have many asking if current security best practices are enough. But this is not a new story. It’s just the latest one.

Last month, health insurance provider Anthem Inc. found its name splashed across news headlines after discovering cyber hackers stole information on tens of millions of Anthem customers. The data breach ranks among the largest in corporate history, with stolen information including customers’ names, birth dates, social security numbers, street addresses, email addresses and employment details (including income). It is yet another example of a large scale breach resulting from the inappropriate use of privileged credentials, also known as the insider credentials threat, and once again demonstrates the challenges of using traditional security solutions to detect and prevent these types of sophisticated attacks.

And just this week it was reported that another member of the healthcare industry experienced a significant breach. Premera Blue Cross has confirmed that a breach exposed the private information of up to 11 million customers including names, date of birth, email address, home address, telephone number, member identification number, bank account information, claims information and clinical information. Premera discovered the attack on January 29th, 2015, but their investigations indicated that the initial attack occurred on May 5th, 2014.

Unfortunately, the lesson learned from these incidents is an unfair one: It only takes an attacker one successful attempt to cause significant damage, yet organizations are on the hook to try to prevent attacks 100 percent of the time. This is simply not a feasible approach. So the real lesson here for the healthcare industry, and any other industry, is that the attack will occur and you must immediately evaluate and improve your ability to detect activity on your network that’s anomalous or suspicious.

In Anthem’s case, they detected the breach itself, and that’s not the norm. Typically a company learns about a breach from a third party. This attack was discovered when a database administrator noticed a query running with his account that he didn’t initiate. So let’s not beat up on Anthem because they did find this themselves, and that is a real credit to the training and awareness of its personnel.

However, it did take at least six weeks for the firm to discover that its security had been breached and there is no real way of knowing right now how long the infiltrators were operating on their network. Anthem calls the breach the result of a “very sophisticated external Cyber attack,” and relayed that law enforcement agencies are still working to identify the perpetrator.

According to information shared publicly, the attackers had legitimate credentials to the database and used them to access the data. That’s an indication that we all have to carefully monitor the use of credentials. It’s likely the credentials could have been strong, and while one could argue stronger measures in place like two-factor authentication may have prevented this particular incident, it only takes an attacker one successful attempt to penetrate the network.

We don’t know much about how the Premera attack occurred at this time, but the infosec community has identified similarities between the Premera attack and the Anthem attack.  The conclusion that cannot be denied at this time, however, is that the healthcare industry is a target – attacks of this type will likely continue, as will the breaches.

Healthcare organizations must ensure a balance between preventative and detection controls. If Anthem had the capability to detect anomalous queries running sooner, they likely could have prevented the breach, or at least lessened the scope of the damage. This requires the ability to detect that something out of the ordinary has occurred. For example, alert when a query is initiated and running when an employee’s not at work.

Analytics can be used to help identify deviations from typical system network connectivity through the collection and analysis of network flow data resulting from communications across the network and between different systems and applications, including external cloud-based services, and provide real time alerts when they detect deviations from normal or typical network behavior.

So while it may look like an overwhelming task, I’d like to suggest a set of best practices that any size healthcare payer or provider can implement to improve its security posture:

●Initiate a risk assessment: Start by asking several questions, and you must be brutally honest and self-critical with the answers:

1.Are we able to detect inappropriate use of authorized credentials (the insider credential threat)?

2.Can we detect the loss of a credential?

3.What about activities of an employee authorized to use credentials who may be acting maliciously?

4.How about the employee who may be acting inappropriately, but not maliciously?

5.How can we detect suspicious activities sooner?

●Recognize this is not just a technology issue: A company needs to regularly train all employees and have the processes in place to help identify and remediate threats quickly.

●Implement an asset management system: An absolute necessity in order to create all possible scenarios to determine your ability to detect and help prevent breaches.

In today’s business environment where employees are increasingly mobile and accessing information from multiple devices and information is stored inside and outside the company firewall, knowing what you have, where it resides and the sensitivity of that information is a must.

By  Andrew Wild

About Lancope

Lancope, Inc. is a leading provider of network visibility and security intelligence to defend enterprises against today’s top threats. By collecting and analyzing NetFlow, IPFIX and other types of flow data, Lancope’s StealthWatch® System helps organizations quickly detect a wide range of attacks from APTs and DDoS to zero-day Malware and insider threats. Through pervasive insight across distributed networks, including mobile, identity and application awareness, Lancope accelerates incident response, improves forensic investigations and reduces enterprise risk. Lancope’s security capabilities are continuously enhanced with threat intelligence from the StealthWatch Labs research team.For more information, visit www.lancope.com.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}