Mississippi Division of Medicaid
Disclosed May 26, 20179 years ago5,220 affectedConfirmed
On April 7, 2017 the covered entity (CE), Mississippi Division of Medicaid, discovered that beginning on May 2, 2014, an employee had used WuFoo, an online service, to create and post online forms to the CE’s external website for public use. While these forms were secure on the CE’s and WuFoo’s websites, they were not encrypted when emailed between Wufoo and the CE’s employees. These forms requested protected health information (PHI) from beneficiaries. As the form information was transmitted via unencrypted email across the public internet, the CE was unable to determine whether a third party inappropriately accessed the form information contained in these emails. The CE did not have a Business Associate Agreement (BAA) with WuFoo. The PHI contained in the unsecured forms included: beneficiary or potential applicants’ names, addresses, emails, enrollment dates, Medicaid and/or Medicare identification numbers, social security numbers, phone numbers, clinical information, and health plans. Approximately 4,524 people were affected by the breach. The CE provided breach notification to HHS, affected individuals, and the media, and also provided substitute notice on its website. Followi
What is known
| People affected | 5,220 (as reported to HHS) |
|---|---|
| Disclosed | May 26, 2017 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Insurance · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Mississippi Division of Medicaid (Health Plan, MS)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | May 26, 2017 | 5,220 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.