Premera Blue Cross , a Washington-based insurance company, has been fined $6.85 million for a data breach that could have exposed more than 10 million health information. The fine would be the second largest ever paid to the Department of Health and Human Services ' Office of Civil Rights .

The incident was the result of a phishing email , when malicious actors sent an email in 2014 that installed malware that gave them access to Premera's IT system . The hackers reportedly accessed names, addresses, Social Security numbers, bank account information and clinical information from the company's health plans. The breach, however, was not detected until January 2015.
In its investigation, OCR said that Premera failed to assess the potential risks and vulnerabilities of its system for protected health information and that it did not implement risk management. In addition to the fine, the company will be required to implement a series of corrective actions and its progress will be monitored for two years. The company will also be required to submit a risk analysis and risk management plan, which will be approved by the Office for Civil Rights.

“If large health insurers don’t invest the time and effort to identify their security vulnerabilities, whether technical or human, hackers,” OCR Director Roger Sevrino said in a press release. “This case vividly illustrates the damage that results when hackers are allowed to roam undetected in a system for nearly nine months.”
A federal judge in Oregon approved a separate settlement in March, in a lawsuit filed after the breach. Under that agreement, Premera will put $32 million into a settlement fund to cover the cost of credit monitoring services and identity theft insurance for members. The company will also spend $42 million to beef up its security over the next three years.
