FEDERALMalwareHealthcareFinancial ServicesHealthcareRansomwareBusiness Associate (HIPAA)Supply Chain (3P Vendor)Data EncryptedCustomer Data InvolvedRansom DemandedDelayed DiscoveryHEALTH_BASICIDENTITY_BASICLowResolved
Molina Healthcare
bd_d0b82c76fffb1613 · schema v1 · pii pii-v1
Full breach record for Molina Healthcare →Molina Healthcare (CA, Health Plan) reported to HHS on 2019-02-22 a Hacking/IT Incident (ransomware) affecting 895 individuals. On Sept. 23, 2018, Wolverine Solutions Group — a subcontractor of business associate Equian, LLC — suffered a ransomware attack. Molina was notified on Dec. 27, 2018. Affected ePHI included names, addresses, health plan names, dates of service, and provider names across six states. Breached information located on Network Server. Remediation included HIPAA training for the BA and mandatory security enhancements at the subcontractor.
HIPAA clockDiscovered Dec 27, 2018 → Notified Feb 22, 201957d ✓ HIPAA 60-day OK8 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed895 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Feb 22, 2019
- Raw hash
- a78e3970cfb473f3e0da0a37216fc3216c13c263085e4d213280bf29fea78f0a
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Molina Healthcarenorm: molina healthcare
- Domain
- molinahealthcare.com
- Industry
- Insurance — Health
Victim entity
- Name
- Molina Healthcarenorm: molina healthcare
- Domain
- molinahealthcare.com
- Industry
- Insurance — Health
- Industry
- Healthcaresource defaultFinancial Servicesllm
Incident
- Discovered
- Dec 27, 2018
- Materiality determined
- —
- Notification sent
- Feb 22, 2019
- Affected individuals
- 895
- Data types
- HEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access· Wolverine Solutions Group (subcontractor)
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- OCR reviewed applicable BA contracts and obtained assurances that corrective action steps were implemented.
- Third party
- via Wolverine Solutions Group (subcontractor)
Compliance
- Time to disclose
- 8 weeks(57 days from discovery to filing)
- Compliance flags
- HIPAA 60-day OK · 57dHHS notified · 57d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Dec 27, 2018→ Notified: Feb 22, 201957d 60 days HIPAA 60-day OK HIPAA Discovered: Dec 27, 2018→ Notified: Feb 22, 201957d regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.