Notice: Personal Health Information Disclosed
Public Notice from Maximus Health Services, Inc. (Maximus) on behalf of the Virginia Department of Medical Assistance Services (DMAS). DMAS is Virginia’s Medicaid agency, and Maximus contracts with DMAS to support Medicaid’s Operations. We are alerting you because on July 22, 2022, a Maximus employee emailed documents that contained the protected health information of some Medicaid members to a personal email account. Your information may have been included in one of the documents.
Keeping your protected health information safe is our top priority. We are taking this matter very seriously.
What Happened
DMAS contracts with Maximus to oversee its Cover Virginia operations center. On July 22, 2022, a Maximus employee emailed documents from the secure Maximus network to their personal email account. The documents contained protected health information of some Medicaid members. The types of information contained in the documents may include: applicant (and household members) names, addresses, phone numbers, email addresses, dates of birth, health plan names, medical conditions, race/ethnicity, application identification numbers, case/client/inmate numbers, and/or Medicaid ID numbers. No credit card or banking information was involved.
The incident happened on the employee’s last day of work at Maximus. Maximus discovered the issue during a security review on August 18, 2022. Maximus reported the issue to DMAS on August 19, 2022. At this time, although Maximus does not have any reason to believe that anyone other than this former employee viewed the emailed documents containing protected health information for you or other Medicaid members, we are notifying you of this incident out of an abundance of caution.
We requested that the former employee delete the emails and attachments, and the former employee provided assurance that the information was not kept, forwarded, or shared by the former employee.
What We Are Doing
The DMAS Information Security Officer is leading the investigation into this disclosure and will continue to monitor Maximus’s operations to ensure confidential and private data is protected and secure. DMAS has reported this incident to relevant state and federal authorities. Maximus is continuing to work with DMAS to review this matter. We are also updating our security tools to help prevent this from happening in the future.
What You Can Do To Protect Your Personal Information
As good practice, it is recommended that you regularly monitor your account statements for any irregularities.
We regret this incident and we take the privacy and security of your personal information very seriously. You can contact Maximus with questions or concerns at 1-855-242-8282, or in writing to questions@maximus.com.