Gainwell Technologies and Connecticut Department of Social Services: State says data from 41,000 Medicaid members exposed in portal breach

Gainwell Technologies and Connecticut Department of Social Services: State says data from 41,000 Medicaid members exposed in portal breach

Connecticut Medicaid Data Breach Exposes Payment and Claims Info for 41,000 Members

A data breach in Connecticut’s Medicaid program, managed by fiscal agent Gainwell Technologies, exposed payment and claims details for approximately 41,000 HUSKY Health members. The incident was detected on June 25, 2026, after an unauthorized party accessed a provider’s reimbursement account.

While electronic health records, Social Security numbers, and financial account details remained unaffected, compromised data may have included names, Medicaid ID numbers, service dates, billing information, payment amounts, and external health insurance policy details such as group and policy numbers. Authorities suspect a financial motive behind the breach rather than an attempt to obtain sensitive patient data.

Following the discovery, Gainwell implemented enhanced security measures on the provider portal. Commissioner Andrea Barton Reeves of the Connecticut Department of Social Services (DSS) emphasized the state’s commitment to patient privacy, noting that the breach was contained through Gainwell’s swift response. The agency is collaborating with cybersecurity experts and law enforcement at both the state and federal levels to investigate the incident and reinforce protections.

Affected individuals began receiving mailed notifications on August 21, 2026, offering free credit monitoring, identity protection, and fraud assistance services. Those with concerns can contact a dedicated hotline at 1-866-200-0986. The investigation remains ongoing.

Source: https://www.wfsb.com/2026/08/21/state-says-data-41000-medicaid-members-exposed-portal-breach/

Gainwell Technologies TPRM report: https://www.rankiteo.com/company/gainwell-technologies

Connecticut Department of Social Services TPRM report: https://www.rankiteo.com/company/stateofconnecticut

"id": "stagai1787430483",
"linkid": "stateofconnecticut, gainwell-technologies",
"type": "Breach",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '41,000 HUSKY Health members',
                        'industry': 'Healthcare IT / Medicaid Management',
                        'location': 'Connecticut, USA',
                        'name': 'Gainwell Technologies',
                        'type': 'Fiscal Agent'}],
 'attack_vector': 'Unauthorized access to provider reimbursement account',
 'customer_advisories': 'Free credit monitoring, identity protection, and '
                        'fraud assistance services offered to affected '
                        'individuals.',
 'data_breach': {'number_of_records_exposed': '41,000',
                 'personally_identifiable_information': 'Names, Medicaid ID '
                                                        'numbers',
                 'sensitivity_of_data': 'Moderate (no SSNs or financial '
                                        'account details)',
                 'type_of_data_compromised': 'Payment and claims information, '
                                             'external health insurance policy '
                                             'details'},
 'date_detected': '2026-06-25',
 'date_publicly_disclosed': '2026-08-21',
 'description': 'A data breach in Connecticut’s Medicaid program, managed by '
                'fiscal agent Gainwell Technologies, exposed payment and '
                'claims details for approximately 41,000 HUSKY Health members. '
                'The incident was detected on June 25, 2026, after an '
                'unauthorized party accessed a provider’s reimbursement '
                'account. While electronic health records, Social Security '
                'numbers, and financial account details remained unaffected, '
                'compromised data may have included names, Medicaid ID '
                'numbers, service dates, billing information, payment amounts, '
                'and external health insurance policy details such as group '
                'and policy numbers.',
 'impact': {'brand_reputation_impact': 'Potential impact due to breach of '
                                       'member trust',
            'data_compromised': 'Names, Medicaid ID numbers, service dates, '
                                'billing information, payment amounts, '
                                'external health insurance policy details '
                                '(group and policy numbers)',
            'identity_theft_risk': 'Low (SSNs and financial account details '
                                   'unaffected)',
            'payment_information_risk': 'Moderate (billing and payment '
                                        'information exposed)',
            'systems_affected': 'Provider reimbursement portal'},
 'initial_access_broker': {'entry_point': 'Provider reimbursement account'},
 'investigation_status': 'Ongoing',
 'motivation': 'Financial motive',
 'references': [{'source': 'Cyber Incident Description'}],
 'response': {'communication_strategy': 'Mailed notifications to affected '
                                        'individuals, dedicated hotline '
                                        '(1-866-200-0986)',
              'containment_measures': 'Enhanced security measures on provider '
                                      'portal',
              'enhanced_monitoring': 'Yes',
              'incident_response_plan_activated': 'Yes',
              'law_enforcement_notified': 'Yes (state and federal levels)',
              'remediation_measures': 'Reinforced protections, collaboration '
                                      'with law enforcement',
              'third_party_assistance': 'Cybersecurity experts'},
 'stakeholder_advisories': 'Commissioner Andrea Barton Reeves emphasized '
                           'commitment to patient privacy and swift response.',
 'title': 'Connecticut Medicaid Data Breach Exposes Payment and Claims Info '
          'for 41,000 Members',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.