Molina Healthcare In
Disclosed Dec 16, 201312 years ago1,499 affectedConfirmed
A business associate (BA), Molina Healthcare of Virginia, for the covered entity (CE), Fairfax County, Virginia, used a subcontractor, Health Business Systems, Inc. (HBS), a subsidiary of Catamaran/HBS. An employee of HBS placed a pharmacy claims report containing the protected health information (PHI) of 1,499 individuals in a non-secured file transfer protocol (FTP) site when troubleshooting issues during a systems conversion. Upon discovering the breach, Catamaran/HBS notified the BA, conducted a thorough investigation and removed the file from the non-secure server. A copy of the file was encrypted and password protected. The CE provided breach notification to HHS. Affected individuals were offered free identify theft protection. Following this breach, Catamaran/HBS retrained employees, updated its security software and enabled an alert feature when files containing potential PHI are saved on an FTP server. OCR obtained written assurance that the CE implemented the corrective action listed above.
What is known
| People affected | 1,499 (as reported to HHS) |
|---|---|
| Disclosed | Dec 16, 2013 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Molina Healthcare In (Business Associate, CA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Dec 16, 2013 | 1,499 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.