Data leak

Centene Corporation Missing Hard Drives (950K Members)

πŸ“… 2016-01-07
Primary Source β†—

Incident Details

On January 7, 2016, Centene Corporation β€” one of the largest Medicaid-focused managed care organizations in the United States, operating health plans in over 25 states β€” discovered that six unencrypted hard drives used to store member data for a health outcomes improvement project had gone missing. The drives could not be located. Centene disclosed the incident publicly on January 25, 2016. Approximately 950,000 health plan members whose laboratory services were processed between 2009 and 2015 were affected. Exposed data included names, dates of birth, Social Security numbers, member identification numbers, addresses, and laboratory test results. No financial, payment, or credit card data was stored on the drives. Centene offered all affected members free credit and healthcare monitoring services. The incident highlighted a persistent HIPAA compliance gap: unencrypted portable storage devices and hard drives containing protected health information. The $17.3 billion company (at the time) subsequently implemented enhanced encryption requirements for portable media. Centene merged with WellCare Health Plans in 2020, creating one of the largest Medicaid and Medicare managed care organizations in the U.S.

Technical Details

Initial Attack Vector
Physical loss β€” six unencrypted hard drives containing health plan member data were misplaced and could not be located during an IT data project; the drives were being used to store laboratory test result data for a health outcomes improvement initiative

Timeline

  1. 2016-01-07 Breach occurred
  2. 2016-01-25 Publicly disclosed
  3. 2016-01-25 Customers notified