Anthem hackers had compromised the credentials of five different employees
richmond.com
richmond.com
"Anthemfacts.com" was registered on Dec 13th which was, assuming US rather than GMT, the following friday.
The proximity and order of those dates cannot be coincidence. It would seem someone at Anthem was confident enough to start prepping the PR campaign almost TWO MONTHS before the public, or the Conn AG, was notified. And during tax season!
The Wall Street Journal[1] notes that: "Federal law requires health-care companies to inform consumers and regulators when they suffer a data breach involving personally identifiable information, but they have as many as 60 days after the discovery of an attack to report it." Day 59 is cutting it awfully close.
[1] http://www.wsj.com/articles/health-insurer-anthem-hit-by-hac...
Via Twitter @Antheminc: "Previously, http://AnthemFacts.com hosted information about our mental health coverage: http://ow.ly/IzcZr"
The fact that they filled the website with mental heath data does not detract from the theory that they had knowledge of the breech months ago. It only adds to the theory that they were trying to keep things quiet for as long as legally possible.
Would be much more news-worthy if it were five the same employees!