Connecticut Medicaid program hit by data breach impacting 22,500 patients

Connecticut Department of Social Services (CDSS) said its network has been accessed by an “unauthorized third party,” with the breach also impacting a technology vendor that provides account administrator services to the state Medicaid program.

In a Friday announcement, CDSS said it and Gainwell Technologies first identified the cyber-intrusion on March 25, at which time they launched an investigation with the support of independent experts and federal law enforcement.

The nature of the data breach was not revealed, but was said to involve compromised credentials belonging to a Hartford HealthCare employee at the nonprofit teaching hospital associated with the University of Connecticut. From there, the hacker was able to gain access to Medicaid-related records, which in the state is called HUSKY.

The nefarious user was able to gain access to the HUSKY portal through Hartford HealthCare and access files on patients covered by Medicaid, CDSS confirmed.

While the statement from social services and Gainwell did not specify, typically these types of breaches involve social engineering tactics such as phishing.

The cybercriminal gained access to the login information as early as March 4, Gainwell and CDSS confirmed.

“External investigators have determined that the unauthorized third party’s activities appeared to be financially motivated, rather than directed at obtaining patient data,” they wrote.

The total number of victims is approximately 22,500 individuals, which may include patients and providers alike.

CDSS and Gainwell said the investigation into the breach confirmed the perpetrator was able to download files and no longer had access to the portal, as a result of security response protocols being deployed.

All the same, it appears the hacker potentially had access for 21 days. There was no mention in the statement of ransomware being deployed, with the incident being framed as a targeted access for personal information on Medicaid providers and members.

Subscribe to Health Exec News

Medical records taken

It was confirmed that protected health data was stolen in the breach, but CDSS said it varied from person to person. Details may include full names, ID numbers used for Medicaid, dates of healthcare services, what care patients received, and billing details. 

Social Security Numbers were not taken, and bank account or credit card numbers are safe, the state confirmed.

CDSS added that it began notifying all victims via postal mail on May 22.

For more details, read the full data breach notice by clicking here.

Chad Van Alstin Health Imaging Health Exec

Chad is an award-winning writer and editor with over 15 years of experience working in media. He has a decade-long professional background in healthcare, working as a writer and in public relations.

Subscribe to Health Exec News

Subscribe to Health Exec News