HomeSecurityCMS reports 3.1 million data breach

CMS reports 3.1 million data breach

The federal agency Centers for Medicare & Medicaid Services (CMS) announced earlier this month that the health records and personal information of more than three million health plan beneficiaries were exposed in the Cl0p ransomwarethat took place last year.

See also: Deloitte denies user data is at risk after breach

CMS violation

Hackers stole the data after breaching Wisconsin Physicians Service (WPS) health insurance company , which provided Medicare administrative services.

CMS is a federal agency within HHS that manages the nation's major health care programs, including Medicaid and CHIP.

It oversees programs to ensure they meet federal standards, provides funding, enforces policies and regulations, monitors quality and costs, and helps regulate the Affordable Care Act (ACA) health insurance marketplace.

A press release from CMS on Sept. 6 said the agency and WPS were notifying 946,801 people with Medicare about personally identifiable information exposed in the MOVEit that occurred more than a year ago.

On the same day, CMS reported on the U.S. Department of Health and Human Services (HSS) breach portal that the full number of clients affected by the breach was 3,112,815 individuals.

A CMS spokesperson explained that the discrepancy represented individuals who have either passed away or were not Medicare beneficiaries but whose data WPS had collected as part of its work for CMS.

See also: Dell: Allegations of two data breaches in a few days

According to the CMS press release, WPS applied the security updates from Progress Software, the developer of MOVEit Transfer, in early June 2023 and assumed at the time that its systems were secure.

CMS reports 3.1 million data breach

However, a review of the incident in May 2024 revealed that hackers had breached the WPS network before the company applied the security patch.

On July 8, 2024, while still assessing the stolen breach records, CMS found that they contained, among other things, the following information:

  • Name
  • Social Security Number or Individual Tax Registration Number
  • Date of birth
  • Mailing address
  • Genus
  • Hospital Account Number
  • Service dates
  • Medicare Beneficiary Identifier (MBI) and/or Health Insurance Claim Number

As the investigation into the incident continues, affected individuals are being offered a 12-month free credit monitoring service from Experian to mitigate the risks arising from the exposure of their data.

Although Cl0p claimed to delete data belonging to hospitals, healthcare organizations, and US government entities, it is practically impossible to guarantee that the stolen data has not been shared or sold on the Dark Web.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Critical infrastructures: At risk from email breaches

A data breach, such as the one at CMS, poses a serious threat to companies and organizations around the world. These breaches occur when confidential information is compromised by unauthorized users, often leading to financial losses, reputational damage, and legal consequences for the affected entities. Especially in an era of increasing reliance on digital technologies, protection is more critical than ever. Adopting strong security measures, continuous staff training, and implementing strict privacy policies are essential factors in minimizing the risk of a data breach.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS