CMS hit in MOVEit software breach

The personal health information of 612,000 Medicare beneficiaries has been breached from CMS contractor Maximus Federal Services.

Advertisement

The breach resulted from a vulnerability in the MOVEit software that has also been responsible for third-party breaches at health systems across the country. An unauthorized party gained access to the Maximus files between May 27 and May 31, according to a July 28 CMS news release.

 

The information involved in the breach:

  • Name
  • Social Security number or taxpayer identification number
  • Date of birth
  • Mailing address
  • Telephone number and email address
  • Medicare beneficiary number or health insurance claim number
  • Driver’s license number and state identification number
  • Medical history notes
  • Healthcare provider and prescription information
  • Health insurance claim and policy information
  • Health benefits and enrollment information

 

CMS is notifying affected beneficiaries via letter and providing free credit monitoring services.

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Register to Attend Webinar

The hidden cost of lost clinical time and how leading health systems are responding

Friday, August 7
12:00 PM - 1:00 PM CDT

Presenters: Kassaundra McKnight-Young, Zebra TechnologiesGregory Carras, Zebra TechnologiesJennifer Gene, Levata

Advertisement

Next Up in Cybersecurity

Advertisement

Comments are closed.