DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

91,000 Washington State Apple Health (Medicaid) clients notified of data breach (update1)

Posted on February 9, 2016 by Dissent

The Washington State Health Care Authority issued the following press release today:

State notifies 91,000 Apple Health (Medicaid) clients of data breach by Health Care Authority employee

Employment terminated for individuals involved in data breach; notifying the appropriate federal officials for further investigation and potential criminal review

OLYMPIA – The Washington State Health Care Authority (HCA) discovered that the personal identification information and private health information of more than 91,000 Apple Health (Medicaid) clients was handled improperly by an individual HCA employee. HCA today is sending a notification letter to clients affected by the breach.

The information includes clients’ Social Security numbers, dates of birth, Apple Health client ID numbers, and private health information.

“Our first and foremost priority is protecting our clients’ personal information,” said HCA Risk Manager Steve Dotson. “We have taken swift action to address this issue and help prevent future incidents. I know this is stressful and concerning for those impacted, and we are doing everything possible to support them.”

Two state employees in two state agencies exchanged Apple Health client files in violation of requirements under the federal Health Insurance Portability and Accountability Act (HIPAA). Both employees assert that the exchange of information occurred because the HCA employee needed technical assistance with spreadsheets that contained the data and that the information was not used for any additional unauthorized purposes or forwarded to any other unauthorized recipients. The breach was discovered in the course of a whistleblower investigation into misuse of state resources.

“While we have no indication that the client files went beyond the two individuals involved, Important privacy laws were violated and we are exercising caution and due diligence given the nature of the information,” Dotson said.

Because the investigation could not confirm that the data stayed within the state’s systems, it was determined there was a breach of protected data, requiring client notification.

Both individuals’ employment has been terminated. Upon discovering the breach, HCA:

  •   Conducted an internal investigation that included securing and searching the employee’s computer to understand what information was exchanged.
  •   Partnered with the state agency whose employee was the recipient of the information to further understand what information was exchanged and to ensure HCA information was secure.
  •   Worked to identify files containing private information and notify impacted clients.
  •   Set up one year of free credit monitoring for impacted clients, a toll-free number and a web page for impacted Apple Health clients.HCA covers more than 1.8 million Washington residents through the Apple Health program, which provides free health care to individuals with low incomes.

Update1: Northwest Public Radio subsequently reported some additional details:

One report shows a Health Care Authority worker sent dozens of confidential files to her brother at the Department of Social and Health Services.

The report says she was seeking technical assistance, and the brother completed assignments for her.

That led investigators to search the brother’s work computer.

The report found he spent hours on non-work related sites, including multiple hours on sexually explicit sites where he would view and upload images.

[…]

The health care agency said it could not determine whether clients’ data stayed in state systems, so it determined that a breach had occurred.

Category: Government SectorHealth DataInsiderOtherU.S.

Post navigation

← FDLE investigating Lee County elections website security breach
Former IRS employee pleads guilty in identity theft for tax refund fraud scheme →

1 thought on “91,000 Washington State Apple Health (Medicaid) clients notified of data breach (update1)”

  1. Concerned says:
    February 18, 2016 at 1:37 pm

    How do I file a lawsuit?

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Dutch Government: More forms of espionage to be a criminal offence from 15 May onwards
  • B.C. health authority faces class-action lawsuit over 2009 data breach (1)
  • Private Industry Notification: Silent Ransom Group Targeting Law Firms
  • Data Breach Lawsuits Against Chord Specialty Dental Partners Consolidated
  • PA: York County alerts residents of potential data breach
  • FTC Finalizes Order with GoDaddy over Data Security Failures
  • Hacker steals $223 million in Cetus Protocol cryptocurrency heist
  • Operation ENDGAME strikes again: the ransomware kill chain broken at its source
  • Mysterious Database of 184 Million Records Exposes Vast Array of Login Credentials
  • Mysterious hacking group Careto was run by the Spanish government, sources say

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Period Tracking App Users Win Class Status in Google, Meta Suit
  • AI: the Italian Supervisory Authority fines Luka, the U.S. company behind chatbot “Replika,” 5 Million €
  • D.C. Federal Court Rules Termination of Democrat PCLOB Members Is Unlawful
  • Meta may continue to train AI with user data, German court says
  • Widow of slain Saudi journalist can’t pursue surveillance claims against Israeli spyware firm
  • Researchers Scrape 2 Billion Discord Messages and Publish Them Online
  • GDPR is cracking: Brussels rewrites its prized privacy law

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.