Molina Healthcare
ent_019e0a73b4f123eeefa84aca8a0fa539
Disclosures
4
HHS OCR · 2 jurisdictions
Incidents
—
no linked incident in sample
Max affected reported
54,203
as filed · HHS OCR FEDERAL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Molina Healthcare
- Normalized
- molina healthcare— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300NQQCEQ46YHZ591
- SEC EDGAR CIK
- 0001179929
- Domain
- molinahealthcare.com
Disclosure history (4)newest first
- CALIFORNIAHHS OCRas victim2022-09-09
Molina Healthcare (CA, Health Plan) reported to HHS OCR on 2022-09-09 an Unauthorized Access/Disclosure affecting 8,283 individuals. The covered entity's business associate mailed PHI — including names, member identification numbers, and treatment information — to the wrong recipients (Paper/Films). The CE notified HHS, affected individuals, and the media, and provided credit monitoring and HIPAA training to its BA. OCR provided technical assistance on the HIPAA Security Rule.
- FEDERALHHS OCRas victim2019-02-22
Molina Healthcare (CA, Health Plan) reported to HHS on 2019-02-22 a Hacking/IT Incident (ransomware) affecting 895 individuals. On Sept. 23, 2018, Wolverine Solutions Group — a subcontractor of business associate Equian, LLC — suffered a ransomware attack. Molina was notified on Dec. 27, 2018. Affected ePHI included names, addresses, health plan names, dates of service, and provider names across six states. Breached information located on Network Server. Remediation included HIPAA training for the BA and mandatory security enhancements at the subcontractor.
- FEDERALHHS OCRas victim2015-09-18
Molina Healthcare reported to HHS on 2015-09-18 a theft affecting 54203 individuals, caused by a former employee of its business associate, CVS Health. The employee impermissibly exfiltrated member information, including names and health plan details, to a personal computer. The breached information was located on a Desktop Computer.
- CALIFORNIAHHS OCRas victim2013-12-16
HHS OCR breach report for Molina Healthcare of Virginia (Business Associate) regarding an unauthorized disclosure of PHI involving 1,499 individuals. A subcontractor (HBS) uploaded a pharmacy claims report containing PHI to a non-secured FTP site during troubleshooting. The file was encrypted and password-protected. Remediation included employee retraining, software updates, and offering identity theft protection.
Subsidiary disclosures (5)filed by group companies
◈ These filings were made by or about subsidiaries of Molina Healthcare — not by Molina Healthcare itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- OHHHS OCRvia Molina Healthcare of Ohio, Inc.2023-12-21
Molina Healthcare of Ohio, Inc. reported to HHS on 2023-12-21 an Unauthorized Access/Disclosure affecting 1,977 individuals. A business associate employee mailed PHI — including names, health insurance information, and treatment information — to wrong recipients. Breached information located on Paper/Films. The CE and BA notified affected individuals and media, provided credit monitoring, and implemented additional administrative safeguards. OCR provided technical assistance regarding the HIPAA Rules.
- 🐻California State AGvia Molina Healthcare of California2015-09-18
Molina Healthcare of California, Inc. reported a breach involving Protected Health Information (PHI) and member identifiers. A former CVS employee, acting as a vendor, exfiltrated data from CVS computers on or about March 26, 2015, to fraudulently obtain OTC products. The breach exposed names, CVS IDs, and Rx plan numbers. Molina notified affected members on September 17, 2015, offering identity theft protection and card replacements.
- FEDERALHHS OCRvia Molina Healthcare of New Mexico, Inc.2014-05-10
On behalf of the covered entity, Molina Healthcare of California Partner Plan, Inc., a business associate subcontractor, Molina Healthcare of New Mexico, Inc., printed and mailed postcards to former members that contained a tracking number that, in some cases, was the member’s social security number. Approximately 4,744 individuals were affected. The covered entity provided breach notification, offered one year of free identity theft protection, and revised its HIPAA policies and procedures for mailings.
- TEXASHHS OCRvia Molina Healthcare of Texas, Inc.2013-12-21
Molina Healthcare of Texas, Inc. reported to HHS on 2013-12-21 a breach classified as 'Other' affecting 2,826 individuals. Breached information was located on Paper/Films. No business associate was present. No further detail is available in the web description.
- FEDERALHHS OCRvia Molina Healthcare of California2011-12-17
Molina Healthcare of California reported to HHS on 2011-12-17 a Other breach affecting 11081 individuals. Breached information located on Paper/Films.