MAXIMUS, Inc.
ent_019ed7ec52a3d14f374ea41530de2b88
Disclosures
7
State AG · HHS OCR · 7 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
6,376
as filed · State AG NH
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- MAXIMUS, Inc.
- Normalized
- maximus— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300DQCDS8HJ7QF202
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (7)newest first
- 🏛️Massachusetts State AGas victim2026-07-01
State of Massachusetts Attorney General breach notification for Maximus US Services Inc. The provided source document contains no narrative text or attachment content, preventing extraction of breach details, dates, or affected data types.
- VAHHS OCRas victim2025-04-25
Maximus, Inc. reported to HHS on 2025-04-25 a Unauthorized Access/Disclosure affecting 4955 individuals. Breached information located on Network Server. Business Associate present.
- 🌺Hawaii State AGas victim2023-08-26
Maximus Health Services, Inc. notified Hawaii AG of a security incident involving the MOVEit Transfer vulnerability (Progress Software). Unauthorized access occurred May 27-31, 2023, leading to exfiltration of personal information. Maximus took the environment offline, applied vendor patches, and offered 2 years of credit monitoring. No specific count of affected individuals was provided in this filing.
- 🍁Vermont State AGas victim2023-08-25
Maximus Health Services, Inc. notified consumers of a data breach involving Progress Software's MOVEit Transfer application. An unauthorized party accessed files between May 27-31, 2023, exploiting a vulnerability in the third-party software. Personal information was accessed. Maximus engaged forensic experts, took systems offline, and is offering two years of credit monitoring.
- 💎Delaware State AGas victim2023-08-25
Maximus Health Services, Inc. disclosed a security incident involving the MOVEit Transfer vulnerability (Zero Day). Unauthorized access occurred between May 27-31, 2023, resulting in the exfiltration of personal information. Maximus detected the activity on May 30, 2023, took the system offline, and offered two years of credit monitoring. The incident involved a third-party software vulnerability exploited by an external actor.
- ⛰️New Hampshire State AGas victim2023-08-25
Maximus, Inc. notified the New Hampshire Attorney General of a data security incident involving its MOVEit Transfer environment. An unauthorized party exploited a critical zero-day vulnerability in the third-party software (Progress Software) between May 27 and May 31, 2023, to exfiltrate files containing personal information of at least 6,376 New Hampshire residents. Maximus detected the activity on May 30, 2023, took the system offline, and began notifying residents on August 24, 2023. Remediation included credit monitoring via Experian and cooperation with the FBI.
- 🐻California State AGas victim2021-06-23
Maximus, Inc. reported a cybersecurity incident where an unknown actor accessed a server containing personal information of Ohio healthcare providers. The breach involved names, DOBs, SSNs, and DEA numbers. The server was isolated, forensics were engaged, and law enforcement and ODM were notified. Credit monitoring was offered.