Anthem Data Breach: $115M Settlement, Payments, and Expired Monitoring

The Anthem data breach settlement is closed. All claims from the $115 million class action have been paid or denied, no new submissions are accepted, and no appeals will be considered. If you missed the filing deadline or let a settlement check go stale, there is no mechanism to reopen a claim. One resource does remain live: class members who experience identity fraud tied to the 2015 breach can still reach a certified fraud resolution specialist through Experian.

Current Payment Status

According to the official settlement website, the claims process is fully complete.1Anthem Data Breach Settlement. Anthem Data Breach Initial payments went out by paper check, direct deposit, or prepaid debit card. The fund has been fully distributed. Calling the settlement administrator will not reopen a closed claim, and there is no late-claim process.

The two years of triple-bureau credit monitoring and identity theft protection provided to class members has also expired. That coverage tracked activity across Equifax, Experian, and TransUnion and sent alerts about suspicious changes, but the coverage period has long since ended.

The Fraud Resolution Line That Is Still Open

The one piece of the settlement that has not expired is access to a certified fraud resolution specialist through Experian. If you were a class member and have experienced identity fraud you believe is connected to the Anthem breach, you can still call for help.1Anthem Data Breach Settlement. Anthem Data Breach

The number is 866-579-2216, and the engagement number is DB04939. This is not a general customer service line. It is a dedicated resource for navigating credit repair, disputing fraudulent accounts, and restoring your identity after theft. You will need to explain the fraud event and its connection to the breach. This service was designed as a permanent resource and remains the only active benefit from the settlement.

If You Already Received a Settlement Payment or Service

Credit monitoring and identity protection services provided through the settlement were not taxable income. The IRS addressed data breach situations directly in Announcement 2015-22, stating it would not treat the value of identity protection services provided after a breach as gross income, and employers providing these services to affected employees were not required to report them on W-2 or 1099 forms.2Internal Revenue Service. IRS Announcement 2015-22

Cash payments are treated differently. The IRS guidance explicitly does not cover cash received in lieu of identity protection services. If you chose the $50 alternative cash payment or received reimbursement for out-of-pocket expenses, standard tax rules apply. Most data breach settlement payments for emotional distress or inconvenience, as opposed to physical injury, are generally treated as taxable income. Talk to a tax professional if you have questions about how a prior payment should have been reported.

Why the Risk From This Breach Has Not Gone Away

The 2015 breach exposed personal information belonging to roughly 78.8 million people. Stolen records included full names, dates of birth, Social Security numbers, medical identification numbers, street addresses, email addresses, phone numbers, and employment and income details.3United States Department of Justice. Member of Sophisticated China-Based Hacking Group Indicted for Series of Computer Intrusions, Including 2015 Data Breach of Health Insurer Anthem Inc. Affecting Over 78 Million People Anthem said credit card numbers, banking details, and medical claims information were not part of the breach.4California Department of Insurance. Anthem Data Breach

That distinction matters less than it sounds. A Social Security number combined with a date of birth and address is enough to open credit accounts, file fraudulent tax returns, or take over existing financial accounts. The inclusion of medical identification numbers also opens the door to medical identity theft. Someone using your medical ID can receive treatment under your name, fill prescriptions you never ordered, or exhaust your insurance benefits without your knowledge. The FTC warns that key signs include receiving bills or insurance statements for services you never received, or getting a notice that you have hit your benefit limit when you have not.5Federal Trade Commission (FTC). What To Know About Medical Identity Theft

A stolen credit card can be replaced in days. A Social Security number and medical ID follow you permanently. Criminals have been known to sit on stolen data for years before using it, which is why the risk from this breach does not diminish with time.

Protecting Yourself Now That Monitoring Has Expired

With the settlement’s credit monitoring long expired, ongoing protection is on you. The single most effective step is placing a credit freeze with all three major bureaus: Equifax, Experian, and TransUnion. A freeze blocks anyone from opening new credit accounts in your name, and under federal law it costs nothing to place or lift.6Consumer Advice – FTC. Credit Freezes and Fraud Alerts It does not affect your credit score. When you need to apply for credit yourself, lift the freeze temporarily, then put it back.

A freeze does not cover every risk. It will not stop someone from filing a tax return in your name, using your medical ID at a hospital, or accessing existing accounts. For those, check your IRS tax transcripts during filing season, review every explanation of benefits statement from your health insurer, and monitor your existing bank and credit card accounts for unfamiliar transactions. If you spot signs of medical identity theft, request your medical records and report the fraud to your insurer and the FTC.5Federal Trade Commission (FTC). What To Know About Medical Identity Theft

Because the stolen data includes Social Security numbers that cannot be changed, a credit freeze is not a one-time fix. It is a permanent posture for anyone whose information was part of this breach.

Background on the Settlement and Related Penalties

The class action was consolidated in the U.S. District Court for the Northern District of California, and Judge Lucy Koh granted final approval of the $115 million settlement on August 15, 2018.7U.S. Judicial Panel on Multidistrict Litigation. In Re Anthem, Inc., Customer Data Security Breach Litigation MDL No. 2617 Transfer Order Two tracks of compensation were available to class members: reimbursement of up to $10,000 for documented out-of-pocket losses such as credit freezes, identity protection services, or time spent dealing with fraud; or a flat cash payment of up to $50 for class members without documented losses, taken in lieu of the free credit monitoring. Anthem was also required to make specific security changes, including encrypting certain personal information and restricting access to sensitive data archives.

The class action was not the only consequence. In October 2018, Anthem agreed to pay $16 million to the U.S. Department of Health and Human Services Office for Civil Rights to resolve potential violations of HIPAA’s Privacy and Security Rules, the largest HIPAA settlement at the time.8U.S. Department of Health & Human Services (HHS). Anthem Pays OCR $16 Million in Record HIPAA Settlement Following Largest Health Data Breach in History In 2020, Anthem reached a separate $39.5 million settlement with a coalition of 43 state attorneys general and the District of Columbia, requiring a comprehensive information security program, regular security reporting to its board, and third-party security assessments for three years.

None of these enforcement actions produced additional consumer payments. The class action was the mechanism for individual compensation, and that mechanism is closed.