In February 2015, 80 million customers of Anthem potentially had their personal data stolen by hackers, the largest computer breach ever disclosed by a healthcare company. This was not the first known data breach: Humana, Horizon Blue Cross Blue Shield of New Jersey and QCA Health Plan Inc. of Arkansas have all settled lawsuits based on unencrypted customer data that was lost. Under HIPAA, healthcare plans are not required to encrypt data is doing so would "impose an unreasonable burden, the likelihood of disclosure is low, or they have implemented alternative security measures". Encryption of data is already being done for movement of personal data in and out of databases (Anthem), data loss is increasingly common, and current security is lacking to adequately protect customers.



