25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Wellpoint Agrees to $1.7 Million Settlement for HIPAA Violations

Wellpoint is one of the largest providers of Affiliated Health Plans, with almost 36 million policy holders across the United States. Between October 23, 2009 and March 7, 2010 part of its database of policy holders was accessible to unauthorized individuals.

The security breach was brought to the attention of Wellpoint in March 2010 when a lawsuit was filed in California by an applicant who discovered it was possible to access the electronic Protected Health Information of Wellpoint policy holders. Wellpoint took rapid action to restrict access and began an investigation into the data security breach.

It determined that the personal health data was accessible to unauthorized third parties although it was limited to 31,700 individuals. Names, addresses and contact details were accessible along with health information and social security numbers.

HIPAA demands that breach notifications are sent to all those affected by a security breach to enable them to take action to mitigate any damage caused. The company complied with these regulations and sent notifications informing all those affected by the security breach. It also offered credit monitoring services to all those affected to help mitigate any damage caused.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

As demanded by the Health Information Technology for Economic and Clinical Health Act, Wellpoint issued a breach notification informing the Office for Civil rights of the security breach. The security breach was published on the OCR’s website (as required by American Recovery and Reinvestment Act of 2009) and the OCR conducted an investigation.

Under HIPAA regulations, “appropriate administrative, technical and physical safeguards” must be put in place to ensure that access to ePHI is restricted to authorized personnel only. The OCR determined that the security breach was caused as a result of a failure to implement these safeguards. In a recent announcement, the OCR confirmed that a settlement has been reached with Wellpoint for $1.7 million for the HIPAA violations.

The OCR also announced that during the course of the investigation it conducted a forensic analysis of the data breach and determined that the personal health information of 612,404 persons were exposed in the breach, and not 31,700 as reported by Wellpoint. The OCR website is still showing the data breach as having affected 31,700 individuals on its “wall of shame”, the figure detailed in the original report.
With this 600K breach the total number of people affected by HIPAA breaches is almost 22.8 million.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist