Wellpoint Data Breach Exposes Protected Health Information (PHI)

Published
January 5, 2026
Updated
January 5, 2026
Wellpoint Data Breach Exposes Protected Health Information (PHI)
Anthem, Inc.

Affected by the

Anthem, Inc.

data breach?

Join the Lawsuit

On Oct. 7, 2025, Wellpoint, Inc., a major health insurance provider affiliated with Elevance Health, specializes in Medicaid, Marketplace, and Medicare health plans, reported a significant data breach to the U.S. Department of Health and Human Services (HHS).

According to the official HHS breach disclosure, the incident involved unauthorized access to sensitive information. The specific cause and method of the breach have not been publicly detailed. Further, it is not yet known whether Wellpoint's systems were breached, or if this disclosure is related to previously reported data breaches involving vendors, including Outcomes One and Episource.

The exposed information may have included personally identifiable information (PII) such as names, addresses, dates of birth, Social Security numbers, and protected health information (PHI) like medical records, insurance details, and treatment histories.

The breach’s severity is underscored by the sensitivity of both PII and PHI, which can be used for identity theft or medical fraud if obtained by malicious actors.

Wellpoint's response

In the wake of the breach, Wellpoint initiated an internal investigation to determine the scope and cause of the incident. The company has taken steps to secure its systems and prevent further unauthorized access. Individuals affected by the breach have been notified directly, in accordance with legal requirements, and have likely received guidance on monitoring their accounts and credit reports for suspicious activity.

For those affected, it is important to remain vigilant. Recommended actions include:

  • Monitoring credit reports for any unusual activity
  • Reviewing health insurance statements for unauthorized services
  • Considering placing a fraud alert or credit freeze with major credit bureaus
  • Contacting Wellpoint’s customer service for additional support or questions

Given the nature of the information involved, affected individuals should be cautious about potential phishing attempts or unsolicited communications that reference their health or insurance information.

Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info
  • Affected information types not yet disclosed

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image