MAXIMUS, Inc.
bd_fc831cd1e2cfd124 · schema v1 · pii pii-v1
Full breach record for MAXIMUS, Inc. →7 incidents on fileMaximus, Inc. notified Ohio healthcare providers that an unknown actor impermissibly accessed a Maximus server containing personal information (name, DOB, SSN, DEA number) starting May 17, 2021. Maximus isolated the server, engaged forensic investigators, and notified law enforcement and the Ohio Department of Medicaid. No evidence of misuse was found, but 24 months of credit monitoring via Experian was offered.
J jump to incidentP pin to compareR raw source
Incident timeline
May 17, 2021
Begins
May 19, 2021
Discovered
Jun 26, 2021
Filed
vs. sector median
13 wks faster
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- Massachusetts State AGbd_2e78ef3ff37c02522021-06-23 · +3dVerified
- Oregon State AGbd_95fe17fd51c484b12021-06-23 · +3dVerified
- California State AGbd_ca9899e2f1ee95082021-06-23 · +3dVerified
- Montana State AGbd_15f95b9de6da42402021-06-18 · +8dVerified
Show 4 more filings ↓Show fewer ↑up to 176d gap
- Washington State AGbd_340e22bbd5965c2e2021-06-18 · +8dVerified
- Indiana State AGbd_50f3609197b402ce2021-06-18 · +8dVerified
- Maine State AGbd_c0f90fe419cd58bf2021-06-18 · +8dVerified
- Illinois State AGbd_a407b5166ea935272021-01-01 · +176dCandidate
Filing propagation · 9 filings · 9 states
View merged incident ↗Pattern: first filing Jan 1 (IL), last Jun 26 (SC) — a 176-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.