DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

MD: Medicaid mailing mishap leaks personal information; state blames health exchange contractor

Posted on January 20, 2014 by Dissent

Michael Quander reports:

The Maryland Health Benefit Exchange has another problem on their hands after hundreds of Medicaid enrollment packages were mistakenly mailed to the wrong addresses.

The Maryland Department of Health and Mental Hygiene explained they were first alerted to the problem on Friday. A customer called an enrollment broker saying they had received the wrong Medicaid packet.

The enrollment packets include the customer’s name, date of birth, and Medicaid identification number, according to state health officials.

An investigation has revealed the mailing error affected nearly 400 households and 1,078 people.

The state is blaming the health exchange’s prime contractor, Noridian, for the error:

The state said the company experienced a programming error leaking the personal information.

Read more on ABC2.

In a statement issued January 19, the state says:

The Department of Health and Mental Hygiene announced today that as a result of a programming error by Noridian, the prime contractor for the Maryland Health Benefit Exchange, a small percentage of Medicaid enrollment packages were mistakenly sent to the wrong addresses.

Information in the Medicaid enrollment packet includes name, date of birth, and Medicaid ID number. It does not contain Social Security number, financial information, or medical information. There was no external incursion into the system or security breach by an outside entity.

An initial investigation has found that the error affected up to 383 households with 1,078 individuals. This is fewer than 1% of the number of Marylanders enrolled in Medicaid to date with coverage beginning on January 1.

The issue was identified on Friday, after a consumer contacted the Medicaid enrollment broker and reported receiving the wrong Medicaid enrollment package. The state team immediately took action:

The mailing of enrollment packages was stopped on Friday as the matter was investigated. The Maryland Health Connection Consumer Services Center and Medicaid’s enrollment broker have been instructed how to assist callers who may have received the wrong information.

Over the weekend, staff from Medicaid and IT have worked to trace the problem to its source and assess its scope. This initial review has found that the error was the result of a programming error by Noridian. No other individuals appear to be affected.
The Department will notify directly everyone who has been affected and will send the correct enrollment packages early this week.

Individuals who receive the wrong Medicaid enrollment information should call the Maryland Health Connection Consumer Service Center at 1-855-642-8572. All affected individuals have active Medicaid coverage and can still access services.

Category: Uncategorized

Post navigation

← TN: Debit card info stolen at a Pilot Travel Center
The Biggest Big Data Myths of 2013 →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • The headlines suggested Freedman Healthcare suffered a ransomware attack that affected patient data. The reality was quite different.
  • Runsafe report: Medical device cyberattacks threaten patient care, strain budgets, top concern for healthcare sector
  • Ryuk ransomware’s initial access expert extradited to the U.S. from Ukraine
  • Alleged Geisinger hacker will defend himself pro se.
  • Tallahassee Memorial Healthcare reveals it was also impacted by Cerner/Legacy Oracle cyberattack
  • Hospital cyberattack investigation complete, no formal review needed (1)
  • Largest Ever Seizure of Funds Related to Crypto Confidence Scams
  • IMPACT: 170 patients harmed as a result of Qilin’s ransomware attack on NHS vendor Synnovis
  • DOJ’s Data Security Program: Key Compliance Considerations for Impacted Entities
  • UBS reports data leak after cyber attack on provider, client data unaffected

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • DOJ’s Data Security Program: Key Compliance Considerations for Impacted Entities
  • 23andMe fined £2.31 million for failing to protect UK users’ genetic data
  • DOJ Seeks More Time on Tower Dumps
  • Your household smart products must respect your privacy – including your air fryer
  • Vermont signs Kids Code into law, faces legal challenges
  • Data Categories and Surveillance Pricing: Ferguson’s Nuanced Approach to Privacy Innovation
  • Anne Wojcicki Wins Bidding for 23andMe

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.