Claims and payment information for about 41,000 HUSKY Health members was exposed after an unauthorized user gained access to a Connecticut Medicaid provider reimbursement account.
Get Instant Access to This Article
Subscribe to Hartford Business Journal and get immediate access to all of our subscriber-only content and much more.
- Critical Hartford and Connecticut business news updated daily.
- Immediate access to all subscriber-only content on our website.
- Bi-weekly print or digital editions of our award-winning publication.
- Special bonus issues like the Hartford Book of Lists.
- Exclusive ticket prize draws for our in-person events.
Click here to purchase a paywall bypass link for this article
An unauthorized user accessed a Connecticut Medicaid provider’s reimbursement account and obtained claims and payment information for approximately 41,000 HUSKY Health members, state officials have announced.
The state Department of Social Services said late Friday that the unauthorized access occurred via the HUSKY provider portal and was discovered June 25 by Gainwell Technologies, the state’s fiscal agent and account administrator for the Medicaid program.
HUSKY Health is Connecticut’s public health coverage program, encompassing Medicaid and the Children’s Health Insurance Program. It provides coverage to eligible children, parents and caregivers, pregnant women, adults without dependent children, older adults and people with disabilities, with eligibility generally based on factors including income, age and household circumstances.
The information obtained in the breach included members’ names, dates of medical services, information about services received and how they were billed, and payment amounts, state officials said. Some identification numbers and information about non-Medicaid health insurance, including policy and group numbers, were also exposed, they said.
Social Security numbers, financial account information and electronic health records were not compromised, DSS said.
The agency said the intrusion appeared to be financially motivated rather than an attempt to obtain patient information. DSS did not provide additional details about how the provider account was accessed or whether any money was stolen.
Gainwell secured the provider portal after discovering the unauthorized activity and has since implemented additional security controls, DSS said.
DSS said the agency and Gainwell are working with outside cybersecurity experts and state and federal law enforcement agencies to investigate the incident.
DSS and Gainwell began mailing notifications to affected HUSKY members on Aug. 21. Those affected are being offered free credit and identity monitoring services, along with fraud support services.
The agency said it has found no evidence that the exposed member information has been misused.
Individuals who believe they may have been affected can call 1-866-200-0986 for more information.
