| Course | HIM 422 Ethical and Legal Considerations in Health Information Management |
|---|---|
| Module | Module 2 |
| Paper type | undergraduate milestone summarizing a data breach and its stakeholders |
| Length | About 1,070 words, 6 pages |
| Format | APA 7 student paper |
| School | Southern New Hampshire University |
| Program | BS Health Information Management |
| Updated | September 2026 |
Free sample paper for HIM 422 Module 2
Final Project Milestone One: 78.8 Million Records, the Anthem Breach and the People It Touched
[Student Name]
Southern New Hampshire University
HIM 422: Ethical and Legal Considerations in Health Information Management
Final Project Milestone One
[Instructor Name]
[Date]
The organization, setting and figures below are a composite written as a model document. No real employer, client, colleague or patient is described.
Final Project Milestone One: 78.8 Million Records, the Anthem Breach and the People It Touched
In early 2015, Anthem, then the second-largest health insurer in the United States, announced that attackers had broken into its systems and stolen personal information on tens of millions of people. The final count reached 78.8 million individuals, making it the largest health data breach reported to that point. This milestone summarizes what happened, identifies the stakeholders affected and their interests and introduces the legal frameworks that the next milestones will apply. Facts come from Anthem's public statements, the federal settlement announcement and court records.
How the Attack Happened
The attack began about a year before anyone noticed it. In February 2014, at least one employee of an Anthem subsidiary opened a phishing email designed to look legitimate, which allowed the attackers to install malicious software and gain a foothold. Over the following months they moved through Anthem's network, obtained the credentials of employees with broad access and reached a data warehouse holding member information. No evidence showed that medical, claims or payment card data were taken, but the stolen records included names, birth dates, Social Security numbers, member identification numbers, addresses, email addresses and employment information, including income for some members.
Discovery and Response
In late January 2015, a database administrator noticed a query running under his own credentials that he had not started. Anthem's security team investigated, shut down the access and within days notified the FBI and hired an outside security firm. Anthem announced the attack publicly on February 4, 2015, set up a website and call center, mailed notices to affected individuals and offered two years of free identity protection and credit monitoring. Some affected people were not Anthem members at all but members of other Blue Cross Blue Shield plans whose data passed through Anthem's systems when they received care in Anthem's service areas. In 2019, a federal grand jury indicted members of a China-based hacking group in connection with the attack.
The Breach in Context
Anthem was a turning point in breach history. Liu et al. (2015) studied the breach reports filed with HHS in the four years starting in 2010 and showed that most involved the theft of physical items such as laptops and paper records, with hacking a small share. McCoy and Perlis (2018), extending the analysis through 2017, found that hacking and information technology incidents had become the leading source of breached records, and that a handful of very large incidents at health plans accounted for most exposed records. Anthem is the largest of those incidents.
The entry point was also typical. Gordon et al. (2019) ran simulated phishing campaigns at US hospitals and health systems, and staff clicked roughly one message in every seven. Kruse et al. (2017), in a systematic review of health care cybersecurity, concluded that the industry had lagged others in protective measures while holding data that are valuable to criminals. Anthem's breach shows how one click, combined with broad access and slow detection, can expose an entire membership.
What Remains Uncertain
Some questions cannot be answered from public records. Anthem did not publish its internal forensic report, so the exact path from the first compromised computer to the data warehouse is known only in outline. It is also unclear how much of the stolen information has been used for identity theft, because stolen data sold on criminal markets can surface years later and victims rarely learn where a fraudster obtained their details. This milestone therefore treats the confirmed facts, the entry through phishing, the months of undetected access, the types of data taken and the number of people affected, as the basis for the analysis, and it marks anything else as uncertain rather than filling gaps with assumptions.
Key Stakeholders
The breach reached far beyond Anthem's members. Table 1 lists the main stakeholder groups, how the breach affected each and what each needed from Anthem's response.
Table 1. Stakeholders in the Anthem Breach
| Stakeholder | How affected | Primary interest |
|---|---|---|
| Current and former members | Identifiers and Social Security numbers exposed | Protection from identity theft; honest, timely notice |
| Members of other Blue plans | Data held by Anthem through shared claims processing | Notice and the same protections as Anthem members |
| Employer group customers | Employees' data exposed; human resources burden | Information to share with employees; confidence in the insurer |
| Anthem employees | Credentials used by attackers; heavy response workload | Clear roles, support and fair treatment during investigation |
| Executives and board | Accountability for security governance | Containing harm, cost and reputational damage |
| Federal and state regulators | Duty to enforce HIPAA and state laws | Evidence of compliance and corrective action |
| Law enforcement | Criminal investigation | Preserved evidence and cooperation |
| Shareholders | Financial and legal exposure | Transparent disclosure and recovery |
Note. Prepared by the author from public reports on the breach.
Why Stakeholders Matter to the Analysis
The stakeholder map shows that the people most harmed, the members whose Social Security numbers were taken, had the least control over the events that harmed them. Unlike a password, a Social Security number cannot easily be changed, so the risk of identity theft does not end when monitoring services expire. Employer groups and other Blue plans also depended on Anthem's security without being able to inspect it. These relationships raise ethical questions about duty and trust that Milestone Three will address.
Laws in Play
As a health plan, Anthem is a covered entity under HIPAA. Three parts of the HIPAA rules apply. Under the Security Rule, a plan must protect electronic health data through a mix of management, facility and system controls, beginning with an honest assessment of where its risks lie. The Privacy Rule governs use and disclosure. The Breach Notification Rule sets deadlines for telling people: affected individuals must hear promptly, within 60 days at most once a breach is found, HHS must be told, and prominent media outlets must be informed whenever over 500 residents of one state are involved. State data breach laws and state attorneys general add a second layer, and private lawsuits a third. Milestone Two will examine how each layer produced financial and nonfinancial consequences.
Conclusion
The Anthem breach began with a phishing email, went undetected for months and exposed identifying information for 78.8 million people, including many who never chose Anthem as their insurer. Its stakeholders range from members and employers to regulators and shareholders, each with different interests. Understanding what happened and who was affected is the foundation for judging the breach's impact and for deciding what Anthem, and organizations like it, should have done differently.
References
Gordon, W. J., Wright, A., Aiyagari, R., Corbo, L., Glynn, R. J., Kadakia, J., Kufahl, J., Mazzone, C., Noga, J., Parkulo, M., Sanford, B., Scheib, P., & Landman, A. B. (2019). Assessment of employee susceptibility to phishing attacks at US health care institutions. JAMA Network Open, 2(3), Article e190393. https://doi.org/10.1001/jamanetworkopen.2019.0393
Kruse, C. S., Frederick, B., Jacobson, T., & Monticone, D. K. (2017). Cybersecurity in healthcare: A systematic review of modern threats and trends. Technology and Health Care, 25(1), 1-10. https://doi.org/10.3233/THC-161263
Liu, V., Musen, M. A., & Chou, T. (2015). Data breaches of protected health information in the United States. JAMA, 313(14), 1471-1473. https://doi.org/10.1001/jama.2015.2252
McCoy, T. H., Jr., & Perlis, R. H. (2018). Temporal trends and characteristics of reportable health data breaches, 2010-2017. JAMA, 320(12), 1282-1284. https://doi.org/10.1001/jama.2018.9222
What the HIM 422 Module 2 instructions ask for
HIM 422 Final Project Milestone One usually asks you to summarize a health data breach and identify its key stakeholders. Most versions expect three to five pages in APA 7 drawing on credible sources, such as scholarly articles, government enforcement records and reputable news. Describe what happened, when, how the breach occurred, what information was exposed, how it was discovered and how the organization responded. Then identify stakeholders inside and outside the organization and explain how each was affected and what each needed. Close by naming the laws that apply, since later milestones will build on that foundation. Keep facts traceable to a source, and avoid speculating about what cannot be verified.
How this HIM 422 Module 2 final project milestone one example is built
The milestone summarizes the 2015 Anthem attack: a phishing email opened in February 2014, months of undetected movement, a database administrator who spotted a query he had not run and identifiers for 78.8 million people taken. Anthem's notification, identity protection offer and cooperation with the FBI follow. Liu and colleagues and McCoy and Perlis show hacking overtaking theft as the main source of breached records, while Gordon and colleagues and Kruse and colleagues explain the phishing risk. A stakeholder table covers members, other Blue plans, employers, staff, leaders, regulators, law enforcement and shareholders, and the HIPAA rules and state laws in play close the paper. A short section also marks what public records cannot confirm.
Where the HIM 422 Module 2 rubric puts the points
This first HIM 422 milestone tends to earn marks for an accurate and complete summary of the breach, correct identification of internal and external stakeholders, clear explanation of how each was affected, appropriate sources and APA 7 mechanics. Summaries that score well separate verified facts from assumptions and include the details later milestones need, such as the type of data exposed and the date of discovery. Graders also reward stakeholder analyses that go beyond the obvious, for example people affected through shared claims processing. A brief preview of the applicable laws shows the writer is planning ahead for the impact and recommendation milestones. Clearly labeled uncertainty also earns credit.
HIM 422 Module 2 help: the mistakes that cost points
Breach summaries are marked down when one news story is the only source, blur dates, overstate what was taken or list stakeholders without explaining their interests. Another frequent gap is leaving out how the breach was discovered, which matters for later questions about detection and timeliness. If your course assigns a different breach, such as a ransomware attack on a hospital or an insider snooping case, send the case materials with the milestone guidelines so the summary uses your facts. A custom milestone can follow this pattern of attack, discovery, response, context, stakeholders and laws, and it will cite public records wherever they exist.
Get HIM 422 Module 2 written to your instructions
Send the HIM 422 Milestone One guidelines and the breach your instructor assigned or approved. The milestone will summarize the attack, discovery and response from credible sources, map every stakeholder with their interests and preview the laws in play, delivered in 24 to 48 hours, the first request free. The paper above is an original model document written by our desk, not a submitted student paper and not an official Southern New Hampshire University document.
More HIM 422 papers and related BS Health Information Management samples
- HIM 422 Module 1 Discussion: The Legal System, Tort Law and a Records Subpoena
- HIM 350 Module 7 Project Two: A Communication Technology Improvement Plan
- HIM 215 Module 7 Project Two: A Coding Quality Audit Plan
- HIM 400 Module 6 Data Sharing Short Paper: Exchange, Patient Access and Information Blocking
- HIM 220 Module 8 Discussion: A Closing Reflection on Data Ethics and Bias
HIM 422 Module 2 questions, answered
Where can I find a free HIM 422 Module 2 Final Project Milestone One sample?
The full HIM 422 Module 2 milestone is here: the 2015 Anthem breach summarized from public records, with its stakeholders and the laws in play.
How did the Anthem breach begin?
Public accounts trace it to a phishing email opened by an employee of an Anthem subsidiary in 2014, which let attackers install malware and move through the network.
What information was taken in the Anthem breach?
Names, birth dates, Social Security numbers, member ID numbers, addresses, email addresses and employment information for 78.8 million people.
Who counts as a stakeholder in a health data breach?
Anyone affected by or responsible for the breach, including patients or members, employers, staff, leaders, regulators, law enforcement and investors.
When must individuals be notified of a HIPAA breach?
Without unreasonable delay and no later than 60 calendar days after the breach is discovered.