DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Pharmacy benefits management firm notifies clients’ employees whose data were stolen by employee for tax refund fraud (update1)

Posted on February 14, 2014 by Dissent

Tampa-based My Matrixx provides pharmacy and ancillary services for workers’ compensation programs.

In November 2013, they were contacted by federal law enforcement and notified that a former employee of theirs in Florida was under investigation for filing fraudulent tax returns. By that time, the employee was no longer in their employ, but they were asked not to disclose the breach to anyone. In December, they were given permission to start notifying those whose data may have been accessed or actually misused for tax refund fraud.  Law enforcement provided additional details about their investigative findings in January, and in February, My Matrixx began notifying its clients’ employees who had been affected.

In a notification letter dated February 7, Artemis Emslie, President of My Matrixx, notes that the data theft actually occurred in early 2012 or before then and the fraudulent tax returns were filed in the first half of 2012. No credit card information appears to have been involved but names and Social Security numbers were.

Those affected were offered 12 months of free credit monitoring.

The total number of claimants affected was not indicated in their notification to New Hampshire, but they indicate that it was a “small number of situations.”

The names of their clients whose employees were affected was not included in their report to the state and was redacted in the individual notification letter to a New Hampshire resident.

Update: The breach was reported by ProAssurance to Maryland as affecting 23 Eastern Alliance claimants. I’m still keeping an eye out for other clients who were affected.

 


Related:

  • ModMed revealed they were victims of a cyberattack in July. Then some data showed up for sale.
  • Toys “R” Us Canada customers notified of breach of personal information
  • Gatineau gymnastics centre warns members of possible data breach
  • Data breach in 42 Latvian municipalities: DVI imposes 300,000 euro fine on ZZ Dats
  • Protected health information of 462,000 members of Blue Cross Blue Shield of Montana involved in Conduent data breach
  • Resource: NY DFS Issues New Cybersecurity Guidance to Address Risks Associated with the Use of Third-Party Service Providers
Category: Business SectorInsiderSubcontractorU.S.

Post navigation

← Massachusetts Society for the Prevention of Cruelty to Children notifies vendors after tax information exposed
TD Bank offers UNH students credit monitoring services after e-mail security lapse (update) →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Short-term renewal of cyber information sharing law appears in bill to end shutdown
  • Yanluowang ransomware IAB pleads guilty
  • Lawsuit Alleges Ex-Intel Employee Hid 18,000 Sensitive Documents Prior to Leaving the Company
  • HIPAA, but for non-Covered Entities?
  • Manassas City Public Schools close on Monday due to cyberattack
  • San Joaquin County Superior Court concludes sensitive info leaked in data breach
  • NCCIA arrests man over massive data breach involving millions of Pakistanis
  • Defense Contractors Are Silencing Their Cybersecurity Watchdogs
  • Fourth Circuit Weighs in on Standing in Data Breach Class Actions
  • ALT5 Sigma sues former consultant over alleged data breach

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs
  • Always watching: How ICE’s plan to monitor social media 24/7 threatens privacy and civic participation
  • Who’s watching the watchers? This Mozilla fellow, and her Surveillance Watch map
  • EPIC Publishes New Whitepaper Detailing Privacy Risks of Government Data Mining Programs
  • Modern cars are spying on you. Here’s what you can do about it.

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.