DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

91,000 Washington State Apple Health (Medicaid) clients notified of data breach (update1)

Posted on February 9, 2016 by Dissent

The Washington State Health Care Authority issued the following press release today:

State notifies 91,000 Apple Health (Medicaid) clients of data breach by Health Care Authority employee

Employment terminated for individuals involved in data breach; notifying the appropriate federal officials for further investigation and potential criminal review

OLYMPIA – The Washington State Health Care Authority (HCA) discovered that the personal identification information and private health information of more than 91,000 Apple Health (Medicaid) clients was handled improperly by an individual HCA employee. HCA today is sending a notification letter to clients affected by the breach.

The information includes clients’ Social Security numbers, dates of birth, Apple Health client ID numbers, and private health information.

“Our first and foremost priority is protecting our clients’ personal information,” said HCA Risk Manager Steve Dotson. “We have taken swift action to address this issue and help prevent future incidents. I know this is stressful and concerning for those impacted, and we are doing everything possible to support them.”

Two state employees in two state agencies exchanged Apple Health client files in violation of requirements under the federal Health Insurance Portability and Accountability Act (HIPAA). Both employees assert that the exchange of information occurred because the HCA employee needed technical assistance with spreadsheets that contained the data and that the information was not used for any additional unauthorized purposes or forwarded to any other unauthorized recipients. The breach was discovered in the course of a whistleblower investigation into misuse of state resources.

“While we have no indication that the client files went beyond the two individuals involved, Important privacy laws were violated and we are exercising caution and due diligence given the nature of the information,” Dotson said.

Because the investigation could not confirm that the data stayed within the state’s systems, it was determined there was a breach of protected data, requiring client notification.

Both individuals’ employment has been terminated. Upon discovering the breach, HCA:

  •   Conducted an internal investigation that included securing and searching the employee’s computer to understand what information was exchanged.
  •   Partnered with the state agency whose employee was the recipient of the information to further understand what information was exchanged and to ensure HCA information was secure.
  •   Worked to identify files containing private information and notify impacted clients.
  •   Set up one year of free credit monitoring for impacted clients, a toll-free number and a web page for impacted Apple Health clients.HCA covers more than 1.8 million Washington residents through the Apple Health program, which provides free health care to individuals with low incomes.

Update1: Northwest Public Radio subsequently reported some additional details:

One report shows a Health Care Authority worker sent dozens of confidential files to her brother at the Department of Social and Health Services.

The report says she was seeking technical assistance, and the brother completed assignments for her.

That led investigators to search the brother’s work computer.

The report found he spent hours on non-work related sites, including multiple hours on sexually explicit sites where he would view and upload images.

[…]

The health care agency said it could not determine whether clients’ data stayed in state systems, so it determined that a breach had occurred.


Related:

  • Two more entities have folded after ransomware attacks
  • Data breach feared after cyberattack on AMEOS hospitals in Germany
  • Inquiry launched after identities of SAS soldiers leaked in fresh data breach
  • Michigan ‘ATM jackpotting’: Florida men allegedly forced machines to dispense $107K
  • Premier Health Partners issues a press release about a breach two years ago. Why was this needed now?
  • Government will 'robustly defend' compensation claims from Afghans put at risk by data breach
Category: Government SectorHealth DataInsiderOtherU.S.

Post navigation

← FDLE investigating Lee County elections website security breach
Former IRS employee pleads guilty in identity theft for tax refund fraud scheme →

1 thought on “91,000 Washington State Apple Health (Medicaid) clients notified of data breach (update1)”

  1. Concerned says:
    February 18, 2016 at 1:37 pm

    How do I file a lawsuit?

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Scattered Spider Hijacks VMware ESXi to Deploy Ransomware on Critical U.S. Infrastructure
  • Hacker group “Silent Crow” claims responsibility for cyberattack on Russia’s Aeroflot
  • AIIMS ORBO Portal Vulnerability Exposing Sensitive Organ Donor Data Discovered by Researcher
  • Two Data Breaches in Three Years: McKenzie Health
  • Scattered Spider is running a VMware ESXi hacking spree
  • BreachForums — the one that went offline in April — reappears with a new founder/owner
  • Fans React After NASCAR Confirms Ransomware Breach
  • Allianz Life says ‘majority’ of customers’ personal data stolen in cyberattack (1)
  • Infinite Services notifying employees and patients of limited ransomware attack
  • The safe place for women to talk wasn’t so safe: hackers leak 13,000 user photos and IDs from the Tea app

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Congress tries to outlaw AI that jacks up prices based on what it knows about you
  • Microsoft’s controversial Recall feature is now blocked by Brave and AdGuard
  • Trump Administration Issues AI Action Plan and Series of AI Executive Orders
  • Indonesia asked to reassess data privacy terms in new U.S. trade deal
  • Meta Denies Tracking Menstrual Data in Flo Health Privacy Trial
  • Wikipedia seeks to shield contributors from UK law targeting online anonymity
  • British government reportedlu set to back down on secret iCloud backdoor after US pressure

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.