So I got the letter yesterday. Actually calling it a letter is generous, it was more like a form email that Anthem's PR department clearly workshopped for a week before hitting send. My family's on a Blue Cross plan through my wife's employer, which apparently routes through Anthem's systems, which means our names, birthdates, social security numbers, home address, and, this is the part that got me, income and employment data, all sat in a database that somebody outside the company had access to for who knows how long before anyone at Anthem noticed.
They're saying up to 80 million current and former members and employees. Eighty million. That's not a company getting hacked, that's basically a full backup of a mid-sized country's population getting hacked.
I want to be annoyed at the timeline here more than anything else. The breach itself apparently started weeks before anyone caught it. Anthem found out, went public on February 4th, and it's taken about a week for the actual notification letters to reach people who are, you know, the ones whose social security numbers are now sitting in some database that doesn't belong to Anthem anymore. I don't fault them for not tweeting about it the second they suspected something, that's not how a responsible disclosure process works. But a week between "we told the press" and "we told you, the actual victim" feels backwards.
Here's what I actually did about it, because I figure some of you reading this are Anthem customers too, or work somewhere that uses them, or you'll be in this exact spot with some other company before the year's out. I'd bet money on that happening again in 2015, and I will absolutely be smug about it if I'm right.
First thing I did: called the credit bureaus about freezing my credit. This is the part nobody warns you is annoying. In my state a security freeze costs $10 per bureau, so $30 total, and you have to do it three separate times with three separate companies, each running their own clunky phone tree. Equifax put me on hold for 43 minutes. I timed it because I was doing dishes and got curious whether a full load of dishes takes longer than Equifax's hold music loop. The dishes won by about fifteen minutes.
Anthem is also offering two years of free credit monitoring through an outfit called AllClear ID. I signed up, sure, why not, it's free. But I want to say this clearly: credit monitoring tells you after something bad has already happened to your credit. It's not prevention, it's a smoke detector that goes off once the couch is already on fire. A freeze is prevention. If you only do one of the two things Anthem is pushing, do the freeze, not the monitoring, even though the freeze costs money and the monitoring doesn't.
One more thing worth saying. Anthem keeps repeating that no credit card numbers or medical claim details were part of what got taken. I get why they're leading with that, it's meant to sound reassuring. But a name plus a social security number plus a home address plus where you work is genuinely more useful to someone trying to open a fraudulent line of credit than a credit card number is, because credit card numbers get cancelled and reissued in a day. Your social security number just follows you around for the rest of your life like a bad tattoo you got at nineteen and can't afford to have removed.
I don't have a tidy fix for any of this beyond the freeze. Insurance companies sit on enormous piles of exactly the data identity thieves want most, and there's basically no market pressure pushing them to secure it better, because switching health insurers isn't a choice most of us actually get to make. My employer, or in this case my wife's employer, picks the plan, not us. So the accountability loop here is broken in a pretty fundamental way, and a free two-year subscription to a monitoring service doesn't fix that, it just softens the PR hit.
Going to go check the mailbox again now. Mostly out of habit at this point, mostly bracing for another form letter.