Skip to Main Content
Colorado Attorney General

Phil Weiser

Colorado Attorney General

File A Complaint
  • About Us
    • Attorney General Bio & Photos
    • Vision & Values
    • Senior Staff & Organization
    • Colorado Attorney General Annual Report
    • Attorney General Opinions
    • Budget & Accounting
    • Contact Our Office
  • Sections
    • Administration
    • Civil Litigation & Employment Law
    • Consumer Protection
    • Criminal Appeals
    • Criminal Justice
    • Natural Resources & Environment
    • Division of Community Engagement
    • Revenue & Regulatory Law
    • State Services
  • Careers
    • Attorney & Other Non-Classified Positions
    • Fellowships
    • Internships
    • Classified Staff Positions
    • Other Opportunities to Join our Team
  • Media Center
    • Press Room
    • Colorado Open Records Act – CORA
  • Resources
    • Survivors of Childhood Sexual Abuse
    • Victim Assistance
    • Data Protection Laws
    • Colorado Privacy Act
    • Funding Opportunities
    • Office of Financial Empowerment
    • Code of Colorado Regulations
    • Colorado Revised Statutes
    • Transparency Online Project (TOPS)
  • Licensing
    • Business Resources
    • Collection Agencies & Debt Collectors
    • Credit Services Organizations
    • UCCC Licensing & Notification
    • Debt Management Services Providers
    • Health Club Bonds
    • Repossessors
    • Student Loan Servicer Licensing
    • Telemarketing
  • Recursos en español

Colorado to receive more than $100,000 in multistate settlement over 2014 Anthem data breach

Sept. 30, 2020 (DENVER, Colo.)—Attorney General Phil Weiser today announced that Colorado and 43 other states have resolved their claims against Anthem over a 2014 data breach the health insurance company experienced that may have impacted more than 1.5 million Coloradans. The settlement requires that Anthem establish and maintain substantially improved data protection measures and requires a payment to Colorado of $141,970.
In February 2015, Anthem disclosed that cyber attackers had infiltrated its systems beginning in February 2014, using malware installed through a phishing email. The attackers were ultimately able to gain access to Anthem’s data warehouse, where they harvested names, dates of birth, Social Security numbers, healthcare identification numbers, home addresses, email addresses, phone numbers, and employment information for 78.8 million Americans.
“A data breach of this magnitude can have lasting impacts for Colorado residents,” said Weiser. “This settlement tells businesses that they will be held accountable for protecting the vital information of their customers.”
Through the settlement, Anthem has reached a resolution with the 43-state multistate coalition and California. In addition to the total payment of $39.5 million, Anthem has also agreed to a series of data security and good governance provisions designed to strengthen its practices going forward. These include:
  • implementation of a comprehensive information security program, incorporating principles of zero trust architecture, and including regular security reporting to the Board of Directors and prompt notice of significant security events to the CEO;
  • specific security requirements with respect to segmentation, logging and monitoring, anti-virus maintenance, access controls and two factor authentication, encryption, risk assessments, penetration testing, and employee training, among other requirements;
  • third-party security assessments and audits for three (3) years, as well as a requirement that Anthem make its risk assessments available to a third-party assessor during that term; and
  • a prohibition against misrepresentations regarding the extent to which Anthem protects the privacy and security of personal information.
In the immediate wake of the breach, at the request of the Connecticut Office of the Attorney General, Anthem offered an initial two years of credit monitoring to all affected U.S. individuals.
In addition to this settlement, Anthem previously entered into a class action settlement that established a $115 million settlement fund to pay for additional credit monitoring, cash payments of up to $50, and reimbursement for out-of-pocket losses for affected consumers. The deadlines for consumers to submit claims under that settlement have passed.
To learn more about Colorado’s consumer data protection laws, go to coag.gov/resources/data-protection-laws/.
###
Media Contact:
Lawrence Pacheco
Director of Communications
(720) 508-6553 office | (720) 245-4689 cell
Lawrence.pacheco@coag.gov

Most Recent

Eye care clinics agree to pay combined $520K over illegal Medicaid billing

Jan. 15, 2026 (DENVER) — Attorney General Phil Weiser today announced a settlement with Apex Vision and Wellness, a Greeley-based eye clinic, and Just for Grins Vision, a Fountain-based eye clinic, to resolve allegations that the clinics illegally billed the […]

Attorney General Phil Weiser sues HHS for conditioning funding on discriminatory policy

Jan. 13, 2026 (DENVER) – Attorney General Phil Weiser today joined 11 other attorneys general in suing the U.S. Department of Health and Human Services for unlawfully conditioning billions of dollars in federal funding on states’ agreement to discriminate against […]

Fall semester Safe2Tell data shows reporting shift while critical interventions continue

Jan. 13, 2026 (DENVER) — Safe2Tell saw a decline in fall semester reports compared with last year, even as the period included some of the highest reporting months in the program’s history, according to the monthly report released by the […]

Office of the Attorney General
Colorado Department of Law
Ralph L. Carr Judicial Building
1300 Broadway, 10th Floor
Denver, CO 80203

(720) 508-6000

Contact the Office of the Attorney General

Contact

ACCESSIBILITY STATEMENT

DECLARACION DE ACCESIBILIDAD

Facebook
Twitter
LinkedIn
Instagram
YouTube
BlueSky