DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

91,000 Washington State Apple Health (Medicaid) clients notified of data breach (update1)

Posted on February 9, 2016 by Dissent

The Washington State Health Care Authority issued the following press release today:

State notifies 91,000 Apple Health (Medicaid) clients of data breach by Health Care Authority employee

Employment terminated for individuals involved in data breach; notifying the appropriate federal officials for further investigation and potential criminal review

OLYMPIA – The Washington State Health Care Authority (HCA) discovered that the personal identification information and private health information of more than 91,000 Apple Health (Medicaid) clients was handled improperly by an individual HCA employee. HCA today is sending a notification letter to clients affected by the breach.

The information includes clients’ Social Security numbers, dates of birth, Apple Health client ID numbers, and private health information.

“Our first and foremost priority is protecting our clients’ personal information,” said HCA Risk Manager Steve Dotson. “We have taken swift action to address this issue and help prevent future incidents. I know this is stressful and concerning for those impacted, and we are doing everything possible to support them.”

Two state employees in two state agencies exchanged Apple Health client files in violation of requirements under the federal Health Insurance Portability and Accountability Act (HIPAA). Both employees assert that the exchange of information occurred because the HCA employee needed technical assistance with spreadsheets that contained the data and that the information was not used for any additional unauthorized purposes or forwarded to any other unauthorized recipients. The breach was discovered in the course of a whistleblower investigation into misuse of state resources.

“While we have no indication that the client files went beyond the two individuals involved, Important privacy laws were violated and we are exercising caution and due diligence given the nature of the information,” Dotson said.

Because the investigation could not confirm that the data stayed within the state’s systems, it was determined there was a breach of protected data, requiring client notification.

Both individuals’ employment has been terminated. Upon discovering the breach, HCA:

  •   Conducted an internal investigation that included securing and searching the employee’s computer to understand what information was exchanged.
  •   Partnered with the state agency whose employee was the recipient of the information to further understand what information was exchanged and to ensure HCA information was secure.
  •   Worked to identify files containing private information and notify impacted clients.
  •   Set up one year of free credit monitoring for impacted clients, a toll-free number and a web page for impacted Apple Health clients.HCA covers more than 1.8 million Washington residents through the Apple Health program, which provides free health care to individuals with low incomes.

Update1: Northwest Public Radio subsequently reported some additional details:

One report shows a Health Care Authority worker sent dozens of confidential files to her brother at the Department of Social and Health Services.

The report says she was seeking technical assistance, and the brother completed assignments for her.

That led investigators to search the brother’s work computer.

The report found he spent hours on non-work related sites, including multiple hours on sexually explicit sites where he would view and upload images.

[…]

The health care agency said it could not determine whether clients’ data stayed in state systems, so it determined that a breach had occurred.

Related posts:

  • HCA Healthcare releases statement while hacker puts data up for sale on deep web (update1)
Category: Government SectorHealth DataInsiderOtherU.S.

Post navigation

← FDLE investigating Lee County elections website security breach
Former IRS employee pleads guilty in identity theft for tax refund fraud scheme →

1 thought on “91,000 Washington State Apple Health (Medicaid) clients notified of data breach (update1)”

  1. Concerned says:
    February 18, 2016 at 1:37 pm

    How do I file a lawsuit?

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Qantas customers involved in mammoth data breach
  • CMS Sending Letters to 103,000 Medicare beneficiaries whose info was involved in a Medicare.gov breach.
  • Esse Health provides update about April cyberattack and notifies 263,601 people
  • Terrible tales of opsec oversights: How cybercrooks get themselves caught
  • International Criminal Court hit with cyber attack during NATO summit
  • Pembroke Regional Hospital reported canceling appointments due to service delays from “an incident”
  • Iran-linked hackers threaten to release emails allegedly stolen from Trump associates
  • National Health Care Fraud Takedown Results in 324 Defendants Charged in Connection with Over $14.6 Billion in Alleged Fraud
  • Swiss Health Foundation Radix Hit by Cyberattack Affecting Federal Data
  • Russian hackers get 7 and 5 years in prison for large-scale cyber attacks with ransomware, over 60 million euros in bitcoins seized

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • The Trump administration is building a national citizenship data system
  • Supreme Court Decision on Age Verification Tramples Free Speech and Undermines Privacy
  • New Jersey Issues Draft Privacy Regulations: The New
  • Hacker helped kill FBI sources, witnesses in El Chapo case, according to watchdog report
  • Germany Wants Apple, Google to Remove DeepSeek From Their App Stores
  • Supreme Court upholds Texas law requiring age verification on porn sites
  • Justices nix Medicaid ‘right’ to choose doctor, defunding Planned Parenthood in South Carolina

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.