Supply chain
⛓ Supply Chain
Ohio Medicaid Program Third-Party Breach (June 2021)
Primary Source ↗Incident Details
Ohio Medicaid Providers’ Personal Information Exposed by Vendor | JD Supra. Maximus, a contractor of the State of Ohio’s Medicaid program reported this week that it experienced a data breach that exposed Medicaid health. The incident involved unauthorized access to Maximus’s application that housed Ohio providers’ credentialing and licensing data. The Medicaid health care providers were notified of the incident by Maximus on June 18, and were offered two years of credit monitoring. After everything health care providers have gone through in the last year with COVID, this is the last piece of news they want to hear. Third-party company: Maximus.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Maximus
- Supply Chain Attack
- ✅ Confirmed third-party / vendor compromise
Timeline
- 2021-06-01 Breach occurred
- 2021-06-01 Publicly disclosed