Magellan Health
ent_0357ab9f4646fc1f839e1a7f
Disclosures
18
State AG · HHS OCR · 12 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
1,650,500
nationwide · State AG DE
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Magellan Health
- Normalized
- magellan health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- magellanhealth.com
- Corporate parent
- CENTENE CORPORATION— per SEC Exhibit 21 filing
Disclosure history (18)newest first
- Illinois State AGas victim2024-09-01
MAGELLAN HEALTH SERVICES, INC filed a data-breach notice with the Illinois Attorney General in September 2024 (case 24-09-009). The register records the breach as discovered on April 8, 2024. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- New Hampshire State AGas victim2020-12-22
Magellan Health Inc. filed a supplemental security breach notification with the New Hampshire Attorney General regarding a ransomware attack targeting Lucent Health Solutions, Inc. Magellan, acting as a Business Associate for Lucent Health, processed PHI for 45 New Hampshire residents. The breach exposed names, treatment information, health insurance account details, member IDs, and contact information. Magellan authorized to notify affected individuals by mail around December 17, 2020.
- New Hampshire State AGas victim2020-06-17
Magellan Health Inc. filed a supplemental notice with the New Hampshire Attorney General regarding a ransomware attack. The incident occurred between April 6 and April 12, 2020, initiated by a phishing email. ProLock malware was deployed, leading to data exfiltration from a corporate finance server and employee email boxes. Approximately 2,465 New Hampshire residents were affected. Exposed data included SSNs, financial information, and PHI (names, treatment info, member IDs). Magellan engaged Mandiant for forensics and implemented enhanced security controls.
- Delaware State AGas victim2020-06-15
Magellan Health reported a data breach to the Delaware Attorney General. The breach occurred on 2020-04-06. It was discovered on 2020-04-11. Notice was filed on 2020-06-15. 2,237 Delaware residents were affected. 1,650,500 individuals affected in total. Information involved: authentication, financial account, health basic, identity government.
- California State AGas victim2020-06-12
Magellan Health, Inc. disclosed a ransomware attack discovered on April 11, 2020. An unauthorized actor gained access via a phishing email sent on April 6, 2020. The incident potentially affected personal information including Social Security numbers, financial data, and health records. Magellan engaged Mandiant for investigation and notified the FBI. Remediation included enhanced security protocols and identity monitoring services.
- ARIZONAHHS OCRas victim2020-06-12
Magellan Health Inc. reported a phishing incident affecting approximately 1,013,956 individuals. An employee was targeted via email, leading to the exposure of electronic protected health information (ePHI), including names, addresses, Social Security numbers, and health insurance details. The entity implemented additional administrative, technical, and security safeguards in response.
- MARYLANDHHS OCRas victim2020-06-12
Magellan Healthcare reported to HHS on 2020-06-12 a Hacking/IT Incident affecting 50410 individuals. Breached information located on Email, Network Server. A business associate experienced a ransomware attack; case closed and consolidated.
- New Hampshire State AGas victim2020-05-18
Magellan Health, Inc. notified the NH Attorney General of a ransomware attack discovered on April 11, 2020. The incident, caused by a phishing email, resulted in the deployment of Pro Lock malware and the exfiltration of employee/contractor PII (SSNs, W-2s) from a finance server. Approximately 284 NH residents were affected. Magellan engaged Mandiant and the FBI, contained the threat, and is offering 36 months of credit monitoring.
- South Carolina State AGas victim2020-05-12
Magellan Health Inc. disclosed a ransomware attack discovered on April 11, 2020, following a phishing email on April 6. The incident compromised personal information including SSNs, financial data, and health records. Magellan engaged Mandiant for investigation, notified the FBI, and implemented enhanced security protocols. Affected individuals were offered two years of Experian IdentityWorks monitoring.
- Oregon State AGas victim2020-05-11
Magellan Health Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2020-05-11. The breach occurred during 4/6/2020 - 4/12/2020. The breach was discovered on 4/11/2020. 106,473 individuals were affected. Notice was sent on 5/15/2020.
- California State AGas victim2020-05-11
Magellan Health, Inc. disclosed a ransomware attack discovered on April 11, 2020. An unauthorized actor gained access via a phishing email sent on April 6, 2020, exfiltrated data from a corporate server, and deployed ransomware. Affected data included names, addresses, employee IDs, W-2/1099 details (including SSNs), and in limited cases, usernames and passwords. The company engaged Mandiant for forensics, notified the FBI, and offered three years of identity monitoring.
- Montana State AGas victim2020-05-11
Magellan Health Inc. disclosed a ransomware attack discovered on April 11, 2020, following a phishing email on April 6. The attacker exfiltrated personal data including names, SSNs, and W-2 details from a corporate server. Magellan engaged Mandiant and notified the FBI. Affected individuals were offered three years of Experian IdentityWorks.
- Massachusetts State AGas victim2020-05-11
Magellan Health, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-05-11. 14,997 Massachusetts residents were affected. The report records the breach type as electronic.
- Washington State AGas victim2020-05-11
Magellan Health Inc. reported a ransomware attack discovered on April 11, 2020, following a phishing email on April 6. The attacker deployed ProLock malware and exfiltrated a subset of data from a finance/billing server containing PII (SSNs, W-2s) and employee credentials. 1,228 Washington residents were initially notified; supplemental notice covers 5,119 total affected individuals. Magellan engaged Mandiant and the FBI, contained the threat, and offered credit monitoring.
- Indiana State AGas victim2020-05-11
Magellan Health, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2020-04-06 and was reported on 2020-05-11. 5,158 Indiana residents were affected. 1,650,500 individuals affected in total.
- MARYLANDHHS OCRas victim2019-09-17
Magellan Healthcare (MD, Business Associate) reported to HHS on 2019-09-17 a Hacking/IT Incident affecting 55,637 individuals. An employee was the victim of an email phishing scheme compromising ePHI stored in Email systems. Exposed data included names, dates of birth, Social Security numbers, and diagnoses/treatment information. The CE notified HHS, affected individuals, and the media, retrained staff, and offered credit monitoring.
- Illinois State AGas victim2019-01-01
MAGELLAN HEALTH SERVICES filed a data-breach notice with the Illinois Attorney General during 2019 (case 2019-492). The register records the breach as discovered on May 28, 2019. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2019-01-01
MAGELLAN HEALTH, INC filed a data-breach notice with the Illinois Attorney General during 2019 (case 2019-465). The register records the breach as discovered on July 5, 2019. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
Subsidiary disclosures (newest 10)filed by group companies
◈ These filings were made by or about subsidiaries of Magellan Health — not by Magellan Health itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- MARYLANDHHS OCRvia Magellan Rx Management2022-09-23
Magellan Rx Management reported to HHS on 2022-09-23 a Hacking/IT Incident affecting 13663 individuals. Breached information located on Network Server. Employees of the business associate were victims of an email phishing attack exposing PHI including names, DOB, addresses, and financial/clinical data. The covered entity implemented administrative safeguards and terminated the business relationship.
- MARYLANDHHS OCRvia National Imaging Associates, Inc.2022-05-02
National Imaging Associates, Inc. (MD) reported to HHS OCR on 2022-05-02 an Unauthorized Access/Disclosure affecting 744 individuals. A business associate employee impermissibly shared PHI — including names, addresses, dates of birth, diagnoses, lab results, medications, and treatment information — with an unauthorized individual via laptop. The BA sanctioned the workforce member, implemented additional safeguards, and retrained all staff. The CE notified HHS, affected individuals, and the media.
- California State AGvia National Imaging Associates, Inc.2022-04-22
National Imaging Associates (NIA), a subsidiary of Magellan Health, disclosed that an employee (Physician Clinical Reviewer) shared screen access via Zoom with an unauthorized non-employee guest while reviewing health plan member cases. This occurred between November 1, 2021, and March 8, 2022. The incident was discovered on March 7, 2022. Affected data includes protected health information (diagnoses, treatments, medical history) and demographic data (name, address, DOB). The employee was terminated, and 12 months of identity monitoring were offered.
- MARYLANDHHS OCRvia National Imaging Associates, Inc.2022-04-22
National Imaging Associates, Inc. reported to HHS on 2022-04-22 a Unauthorized Access/Disclosure affecting 616 individuals. Breached information located on Laptop. An employee of the business associate impermissibly shared PHI (names, addresses, DOB, diagnoses, lab results, medications) with an unauthorized individual.
- MARYLANDHHS OCRvia National Imaging Associates, Inc.2020-06-12
National Imaging Associates reported to HHS on 2020-06-12 a Hacking/IT Incident affecting 22560 individuals. Breached information located on Email, Network Server. The incident involved a ransomware attack by a business associate. This case is closed and consolidated into an existing investigation.
- ARIZONAHHS OCRvia Magellan Rx Management2020-06-12
Magellan Rx Management reported to HHS on 2020-06-12 a Hacking/IT Incident affecting 314704 individuals. Breached information located on Email, Network Server. The incident involved a ransomware attack on a business associate. This case is closed and consolidated into an existing investigation.
- Massachusetts State AGvia National Imaging Associates, Inc.2019-12-19
National Imaging Associates, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-12-19. 14 Massachusetts residents were affected. The report records the breach type as electronic.
- Oregon State AGvia Magellan Rx Management2019-12-05
Magellan Rx Management reported a data breach to the Oregon Attorney General. The breach was reported on 2019-12-05. The breach occurred during 4/27/2019 - 5/28/2019. The breach was discovered on 7/5/20197/6/20197/7/20197/12/2019. 739 individuals were affected. Notice was sent on 11/22/2019.
- Massachusetts State AGvia Magellan Rx Management2019-11-27
Magellan Rx Management reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-11-27. 7 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGvia Magellan Rx Management2019-11-27
Magellan Rx Management, a subsidiary of Magellan Health, Inc., notified the NH Attorney General of a phishing incident affecting employee email accounts. Unauthorized access occurred starting May 28, 2019, discovered July 5, 2019. One NH resident's PHI and SSN were potentially exposed. Remediation included securing accounts, enhanced email security, staff training, and offering 12 months of credit monitoring.