Magellan Health discovered in July that employees at two of its subsidiaries, National Imaging Associates and Magellan Healthcare, had fallen victim to phishing attacks. The phishing attack at National Imaging Associates affected 589 Presbyterian Health Plan members, while the attack on Magellan Healthcare impacted 55,637 patients.
Patient data stored on the email accounts included names, dates of birth, member numbers, provider names, health benefit authorization information, dates of service and billing codes. A limited number of Social Security numbers also may have been exposed.
Upon investigation, Magellan Health determined that the attackers hacked the email accounts to distribute spam email, reports the HIPAA Journal. The managed care company said there is no evidence that patient information has been misused.
Since the incident, Magellan Health has adopted additional authentication processes and email security has been enhanced. Additionally, the company improved its employee security awareness training.
More articles on cybersecurity:
Health tech leaders release privacy guidelines for consumer health data
Moody’s: Healthcare cyberattacks on the rise, small hospitals most vulnerable
The role of security in digital healthcare delivery and why it’s a core focus for Hackensack Meridian Health in 2020
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.