Supply chain ⛓ Supply Chain

Ohio Medicaid Program Third-Party Breach (June 2021)

📅 2021-06-01 🏢 Maximus
Primary Source ↗

Incident Details

Ohio Medicaid Providers’ Personal Information Exposed by Vendor | JD Supra. Maximus, a contractor of the State of Ohio’s Medicaid program reported this week that it experienced a data breach that exposed Medicaid health. The incident involved unauthorized access to Maximus’s application that housed Ohio providers’ credentialing and licensing data. The Medicaid health care providers were notified of the incident by Maximus on June 18, and were offered two years of credit monitoring. After everything health care providers have gone through in the last year with COVID, this is the last piece of news they want to hear. Third-party company: Maximus.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Maximus
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2021-06-01 Breach occurred
  2. 2021-06-01 Publicly disclosed