U.S. govt agency CMS says data breach impacted 3.1 million people

U.S. govt agency CMS says data breach impacted 3.1 million people

September 24, 2024 at 02:21PM

The Centers for Medicare & Medicaid Services (CMS) revealed that over three million health plan beneficiaries had their health and personal information exposed in a ransomware attack on Wisconsin Physicians Service. The breach affected individuals with Medicare, compromising sensitive data such as Social Security numbers and mailing addresses. Impacted individuals are being offered credit monitoring services to address potential risks.

From the provided meeting notes, the following key points can be distilled:

1. The Centers for Medicare & Medicaid Services (CMS) recently announced that over three million health plan beneficiaries’ health and personal information was exposed in a ransomware attack conducted on the Wisconsin Physicians Service (WPS) health insurance corporation, a provider of Medicare administrative services.

2. CMS is a federal agency within the U.S. Department of Health and Human Services (HHS) that administers major healthcare programs, including Medicaid and CHIP, overseeing their compliance with federal standards, funding support, policy enforcement, regulation, and oversight of the Affordable Care Act’s health insurance marketplace.

3. According to a CMS press release, 946,801 Medicare beneficiaries’ personally identifiable information was exposed in the MOVEit ransomware attack over a year ago, with a total of 3,112,815 individuals affected.

4. CMS discovered that breached information included sensitive data such as names, Social Security Numbers, dates of birth, addresses, gender, hospital account numbers, dates of service, and Medicare Beneficiary Identifiers (MBIs) and/or Health Insurance Claim Numbers.

5. Impacted individuals have been offered a 12-month free credit monitoring service by Experian to mitigate the risks associated with their exposed data. However, it is noted that there is uncertainty regarding the potential dissemination or sale of the stolen data on the dark web despite claims by the perpetrators.

These summarized takeaways effectively capture the key information and implications discussed in the meeting notes.

Full Article