MOLINA HEALTHCARE, INC.
ent_019e0a73b4f123eeefa84aca8a0fa539
Disclosures
8
HHS OCR · State AG · 3 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
54,203
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- MOLINA HEALTHCARE, INC.
- Normalized
- molina healthcare— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300NQQCEQ46YHZ591
- SEC EDGAR CIK
- 0001179929
- Domain
- molinahealthcare.com
Disclosure history (8)newest first
- CALIFORNIAHHS OCRas victim2023-07-11
Molina Healthcare reported to HHS on 2023-07-11 a Hacking/IT Incident affecting 7702 individuals. Breached information located on Network Server. A business associate experienced the attack, compromising PHI including names, DOBs, and insurance info.
- CALIFORNIAHHS OCRas victim2022-09-26
Molina Healthcare reported to HHS on 2022-09-26 a Hacking/IT Incident affecting 1068 individuals. Breached information located on Network Server. A business associate experienced a cyber-attack compromising PHI including names, identifiers, claims, and treatment info. CE provided credit monitoring and implemented technical safeguards.
- CALIFORNIAHHS OCRas victim2022-09-09
Molina Healthcare (CA, Health Plan) reported to HHS OCR on 2022-09-09 an Unauthorized Access/Disclosure affecting 8,283 individuals. The covered entity's business associate mailed PHI — including names, member identification numbers, and treatment information — to the wrong recipients (Paper/Films). The CE notified HHS, affected individuals, and the media, and provided credit monitoring and HIPAA training to its BA. OCR provided technical assistance on the HIPAA Security Rule.
- CALIFORNIAHHS OCRas victim2019-02-22
Molina Healthcare (CA, Health Plan) reported to HHS on 2019-02-22 a Hacking/IT Incident (ransomware) affecting 895 individuals. On Sept. 23, 2018, Wolverine Solutions Group — a subcontractor of business associate Equian, LLC — suffered a ransomware attack. Molina was notified on Dec. 27, 2018. Affected ePHI included names, addresses, health plan names, dates of service, and provider names across six states. Breached information located on Network Server. Remediation included HIPAA training for the BA and mandatory security enhancements at the subcontractor.
- FLORIDAHHS OCRas victim2017-12-21
Molina Healthcare, Inc. reported to HHS on 2017-12-21 a Unauthorized Access/Disclosure affecting 1380 individuals. Breached information located on Other. Error in preparing mailing lists for business associate Merrill Communications resulted in letters with PHI (names, member IDs, dates of service, physician names) being delivered to incorrect beneficiaries.
- CALIFORNIAHHS OCRas victim2015-09-18
Molina Healthcare reported to HHS on 2015-09-18 a theft affecting 54203 individuals, caused by a former employee of its business associate, CVS Health. The employee impermissibly exfiltrated member information, including names and health plan details, to a personal computer. The breached information was located on a Desktop Computer.
- Washington State AGas victim2015-09-18
Molina Healthcare of Washington reported that a former CVS employee, a third-party vendor administering OTC benefits, impermissibly transferred PHI of 7,767 Washington Medicare members to a personal computer around March 26, 2015. Molina was notified on July 20, 2015. Data included names, IDs, and plan details. CVS replaced cards and offered identity theft protection.
- CALIFORNIAHHS OCRas victim2013-12-16
HHS OCR breach report for Molina Healthcare of Virginia (Business Associate) regarding an unauthorized disclosure of PHI involving 1,499 individuals. A subcontractor (HBS) uploaded a pharmacy claims report containing PHI to a non-secured FTP site during troubleshooting. The file was encrypted and password-protected. Remediation included employee retraining, software updates, and offering identity theft protection.
Subsidiary disclosures (7)filed by group companies
◈ These filings were made by or about subsidiaries of MOLINA HEALTHCARE, INC. — not by MOLINA HEALTHCARE, INC. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- OHIOHHS OCRvia Molina Healthcare of Ohio, Inc.2023-12-21
Molina Healthcare of Ohio, Inc. reported to HHS on 2023-12-21 an Unauthorized Access/Disclosure affecting 1,977 individuals. A business associate employee mailed PHI — including names, health insurance information, and treatment information — to wrong recipients. Breached information located on Paper/Films. The CE and BA notified affected individuals and media, provided credit monitoring, and implemented additional administrative safeguards. OCR provided technical assistance regarding the HIPAA Rules.
- IOWAHHS OCRvia Molina Healthcare of Iowa, Inc.2023-11-22
Molina Healthcare of Iowa, Inc. reported to HHS on 2023-11-22 a Hacking/IT Incident affecting 1,647 individuals. Breached information located on Email. An employee was targeted by a phishing scheme, exposing PHI including names, addresses, DOBs, SSNs, and medical data.
- California State AGvia Molina Healthcare of California2015-09-18
Molina Healthcare of California notified members that a former CVS employee, acting as an insider, stole protected health information (PHI) from CVS computers on March 26, 2015, to fraudulently obtain OTC products. CVS informed Molina on July 20, 2015. Affected data includes names, IDs, and Rx plan details. Molina offered identity theft protection and card replacements.
- NEW MEXICOHHS OCRvia Molina Healthcare of New Mexico, Inc.2014-05-10
On behalf of the covered entity, Molina Healthcare of California Partner Plan, Inc., a business associate subcontractor, Molina Healthcare of New Mexico, Inc., printed and mailed postcards to former members that contained a tracking number that, in some cases, was the member’s social security number. Approximately 4,744 individuals were affected. The covered entity provided breach notification, offered one year of free identity theft protection, and revised its HIPAA policies and procedures for mailings.
- TEXASHHS OCRvia Molina Healthcare of Texas, Inc.2013-12-21
Molina Healthcare of Texas, Inc. reported to HHS on 2013-12-21 a breach classified as 'Other' affecting 2,826 individuals. Breached information was located on Paper/Films. No business associate was present. No further detail is available in the web description.
- TEXASHHS OCRvia Molina Healthcare of Texas, Inc.2013-11-26
Molina Healthcare of Texas, Inc. reported to HHS on 2013-11-26 a Unauthorized Access/Disclosure affecting 2826 individuals. Breached information located on Other. The entity inadvertently mailed CHIP ID cards to wrong households due to a system mismatch.
- CALIFORNIAHHS OCRvia Molina Healthcare of California2011-12-17
Molina Healthcare of California reported to HHS on 2011-12-17 a Other breach affecting 11081 individuals. Breached information located on Paper/Films.