Indiana FSSA said Maximus MOVEit breach exposed 744,000 Medicaid members

Organization
Indiana Family and Social Services Administration
Exploit
Supply Chain Attack
Industry
Government Health Agency

The Indiana Family and Social Services Administration announced in August 2023 that more than 744,000 Indiana Medicaid members had personal information exposed in a data security incident at one of its contractors. The contractor, Maximus Health Services, handles member communications for the state's Medicaid programme and was affected through its use of the MOVEit file transfer application.

The exposure stemmed from the exploitation of a zero-day flaw in MOVEit in late May 2023, the same campaign that swept up hundreds of organisations worldwide. Maximus alerted FSSA to the incident, which the agency then made public.

According to FSSA, the exposed data included names, addresses, case numbers and Medicaid identification numbers. Four members also had Social Security numbers exposed. The affected group consisted of Medicaid members who had received correspondence from Maximus about selecting a managed care entity.

Maximus said it would contact every affected member directly and offered 24 months of complimentary credit monitoring through Experian, along with a toll-free line for questions. FSSA advised members to review credit reports and watch accounts for unusual activity. The agency did not report any misuse of the data at the time of the announcement.

Sources