The breach affects current and former members of the Molina Medicare Options Plus HMO.
According to the notification, a former CVS employee took PHI from CVS’ computers and copied the information to his personal computer. CVS believes the former employee did this purposefully to fraudulently obtain over-the-counter products from CVS, but the health system says they have not found any indications of fraudulent use of stolen PHI.
The incident occurred on or around March 26, and CVS informed Molina of the incident on July 20. Molina Healthcare’s notification letter is dated Sept. 17.
Stolen information includes full name, CVS ID, CVS ExtraCare Health Card number, member ID, prescription plan number, prescription plan state, start date and end date.
More articles on data breaches:
Why are healthcare data breaches so common?
Stolen laptop prompts breach notification at LSU Health
Sutter Health notifies 2,500 of breach after employee improperly emails billing documents
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.