MAXIMUS, Inc.
bd_15f95b9de6da4240 · schema v1 · pii pii-v1
Full breach record for MAXIMUS, Inc. →7 incidents on fileMaximus, Inc. notified Ohio healthcare providers of a cybersecurity incident where an unknown actor accessed a server containing personal information (names, DOBs, SSNs, DEA numbers) starting May 17, 2021. Maximus discovered the breach on May 19, 2021, isolated the server, engaged forensic investigators, and notified law enforcement and the Ohio Department of Medicaid. Affected individuals were offered 24 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
May 17, 2021
Begins
May 19, 2021
Discovered
Jun 18, 2021
Filed
vs. sector median
14 wks faster
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- Washington State AGbd_340e22bbd5965c2e2021-06-18Verified
- Indiana State AGbd_50f3609197b402ce2021-06-18Verified
- Maine State AGbd_c0f90fe419cd58bf2021-06-18Verified
- Massachusetts State AGbd_2e78ef3ff37c02522021-06-23 · +5dVerified
Show 4 more filings ↓Show fewer ↑up to 168d gap
- Oregon State AGbd_95fe17fd51c484b12021-06-23 · +5dVerified
- California State AGbd_ca9899e2f1ee95082021-06-23 · +5dVerified
- South Carolina State AGbd_fc831cd1e2cfd1242021-06-26 · +8dVerified
- Illinois State AGbd_a407b5166ea935272021-01-01 · +168dCandidate
Filing propagation · 9 filings · 9 states
View merged incident ↗Pattern: first filing Jan 1 (IL), last Jun 26 (SC) — a 176-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.