Molina Healthcare investigating breach of patient portal

Managed care and Affordable Care Act exchange insurer Molina Healthcare has shut down its online patient portal after a potential data breach may have exposed protected health information for millions of customers.

According to California Healthline, the company may have been “exposing countless patient medical claims” without needing any authentication, according to cybersecurity expert Brian Krebs. He said a Molina member alerted him that by changing a single number in the website address, it was possible to view others patients’ claims, names and addresses.

“It’s unconscionable that such a basic, Security 101 flaw could still exist at a major healthcare provider,” Krebs said. “This information is more sensitive than credit card data, but it seems less protected.”

The company said it was already aware of the vulnerability and is now conducting an internal investigation to determine if and how much data was exposed.

Read the full article at the link below: 

""
John Gregory, Senior Writer

John joined TriMed in 2016, focusing on healthcare policy and regulation. After graduating from Columbia College Chicago, he worked at FM News Chicago and Rivet News Radio, and worked on the state government and politics beat for the Illinois Radio Network. Outside of work, you may find him adding to his never-ending graphic novel collection.

Around the web

Given the precarious excitement of the moment—or is it exciting precarity?—policymakers and healthcare leaders must set directives guiding not only what to do with AI but also when to do it. 

The final list also included diabetes drugs sold by Boehringer Ingelheim and Merck. The first round of drug price negotiations reduced the Medicare prices for 10 popular drugs by up to 79%. 

HHS has thought through the ways AI can and should become an integral part of healthcare, human services and public health. Last Friday—possibly just days ahead of seating a new secretary—the agency released a detailed plan for getting there from here.