State Medicaid Data Breaches: A Growing Pattern of Vulnerability
Tracking security incidents affecting millions of vulnerable Americans
TOTAL RECORDS EXPOSED
47.2M
Medicaid beneficiaries affected since 2015
AVERAGE BREACH SIZE
89,400
records per incident in state Medicaid systems
2024 BREACHES
128
reported to HHS affecting 500+ individuals
MEDIAN DISCOVERY TIME
67 days
from breach occurrence to detection
Records Exposed Over Time
Major Incidents
Illinois — 752K records
Ransomware attack on IL Medicaid contractor
Notification delay: 89 days
Florida — 1,240K records
Unauthorized access to FL Agency for Health Care Administration
Notification delay: 73 days
Texas — 968K records
TX Health and Human Services data exposure
Notification delay: 104 days
California — 1,580K records
CA DHCS third-party vendor breach
Notification delay: 67 days
Policy Milestones
CMS issues initial cybersecurity guidance
First comprehensive guidance for state Medicaid agencies
HIPAA enforcement increases
HHS OCR announces enhanced breach penalty structure
Healthcare sector alert
CISA warns of increased ransomware targeting health data
CMS security rule update
New technical safeguard requirements for state agencies
Understanding Medicaid Data Breaches
Data Sources:
HHS Office for Civil Rights Breach Portal
CMS State Medicaid Agency Reports
ITRC Data Breach Report
Data sources
Breach Portal: Notice to the Secretary of HHS Breach of Unsecured Protected Health Information· U.S. Department of Health & Human Services, Office for Civil RightsMedicaid IT Supplemental Guidance· Centers for Medicare & Medicaid Services2024 Data Breach Report· Identity Theft Resource CenterHealthcare Cybersecurity: Sector Threat Briefing· Cybersecurity and Infrastructure Security Agency