Skip to content

Magellan Health

Disclosed May 11, 20206 years ago1,650,500 affectedConfirmed

Official notice

The covered entity (CE), Magellan Health, reported that an employee was the victim of an email phishing scheme that affected the electronic protected health information (ePHI) of approximately 1,013,956 individuals. The ePHI involved included names, addresses, Social Security numbers, health insurance information, and other treatment information. In its mitigation efforts, the CE implemented additional administrative, technical, and security safeguards to better protect its ePHI.

What is known

People affected1,650,500 (as reported by the organization)
DisclosedMay 11, 2020
DiscoveredApr 11, 2020
HappenedApr 6, 2020
AttackRansomware
Data exposedNames, Health, Credentials and tokens, Social Security numbers, Payment cards, Financial
SectorHealthcare · US
StatusConfirmed

Sources

Source
California Attorney General breach notice: Magellan Healthoag.ca.gov · Official notice
Washington Attorney General breach notice: Magellan Healthatg.wa.gov · Official notice
Delaware DOJ breach notice: Magellan Healthattorneygeneral.delaware.gov · Official notice
Oregon DOJ breach notice: Magellan Healthjustice.oregon.gov · Official notice
Indiana Attorney General 2020 data breach report: Magellan Healthin.gov · Official notice
Maine Attorney General breach notice archive: Magellan Healthmaine.gov · Official notice
HHS OCR breach report (archive, resolved): Magellan Health (Health Plan, AZ)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
California AGresidents of CAMay 11, 2020
Washington AGresidents of WAMay 11, 20205,119
Oregon DOJresidents of ORMay 11, 2020106,473
Indiana AGresidents of INMay 11, 20205,158
Maine AGresidents of MEMay 11, 2020
California AGresidents of CAJun 12, 2020
Maine AGresidents of MEJun 12, 20202,231
HHS archivetotalJun 12, 20201,013,956
Delaware DOJresidents of DEJun 15, 20202,237
History of this record
  • 2026-09-25 · summary: empty to The covered entity (CE), Magellan Health, reported that an employee was the victim of an email phishing scheme that affected the electronic protected health information (ePHI) of approximately 1,013,956 individuals. The ePHI involved includ · backfill source
  • 2026-09-25 · data_types: ["names","health","credentials"] to ["names","health","credentials","ssn","payment-card","financial"] · backfill source
  • 2026-09-25 · source: empty to https://www.in.gov/attorneygeneral/consumer-protection-division/id-theft-prevention/files/DB-Year-to-Date-Report-2020.pdf · backfill source
  • 2026-09-25 · data_types: [] to ["names","health","credentials"] · backfill source
  • 2026-09-25 · records_basis: empty to organization · backfill source
  • 2026-09-25 · records: empty to 1650500 · backfill source
  • 2026-09-25 · attack: unknown to ransomware · backfill source
  • 2026-09-25 · discovered: empty to 2020-04-11 · backfill source
  • 2026-09-25 · disclosed: 2020-06-12 to 2020-05-11 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about Magellan Health

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.