Magellan Health
ent_0357ab9f4646fc1f839e1a7f
Disclosures
8
State AG · HHS OCR · 7 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
1,013,956
as filed · HHS OCR AZ
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Magellan Health
- Normalized
- magellan health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- magellanhealth.com
- Corporate parent
- Centene Corporation— per SEC Exhibit 21 filing
Disclosure history (8)newest first
- 🐻California State AGas victim2020-06-12
Magellan Health, Inc. disclosed a ransomware attack discovered on April 11, 2020, following a phishing email on April 6, 2020. The incident compromised personal information including SSNs, financial data, and health records. Magellan engaged Mandiant for forensics, notified the FBI, and offered credit monitoring. No specific victim count was provided in the filing.
- AZHHS OCRas victim2020-06-12
Magellan Health Inc. reported a phishing incident affecting approximately 1,013,956 individuals. An employee was targeted via email, leading to the exposure of electronic protected health information (ePHI), including names, addresses, Social Security numbers, and health insurance details. The entity implemented additional administrative, technical, and security safeguards in response.
- 🌴South Carolina State AGas victim2020-05-12
Magellan Health Inc. disclosed a ransomware attack discovered on April 11, 2020, following a phishing email on April 6. The incident compromised personal information including SSNs, financial data, and health records. Magellan engaged Mandiant for investigation, notified the FBI, and implemented enhanced security protocols. Affected individuals were offered two years of Experian IdentityWorks monitoring.
- 🦫Oregon State AGas victim2020-05-11
Magellan Health Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2020-05-11. The breach occurred during 4/6/2020 - 4/12/2020. The breach was discovered on 4/11/2020. 106,473 individuals were affected. Notice was sent on 5/15/2020.
- 🐻California State AGas victim2020-05-11
Magellan Health, Inc. disclosed a ransomware attack discovered on April 11, 2020, following a phishing email on April 6, 2020. The attacker exfiltrated personal information including names, addresses, SSNs, and tax details from a corporate server before deploying ransomware. Magellan engaged Mandiant for forensics, notified the FBI, and offered three years of Experian IdentityWorks to affected individuals.
- 🦬Montana State AGas victim2020-05-11
Magellan Health Inc. reported a data breach to the Montana Attorney General. The breach was reported on 2020-05-11. The breach occurred from 4/6/2020 to 4/12/2020. 823 Montana residents were affected.
- 🌲Washington State AGas victim2020-05-11
Magellan Health Inc., a health sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2020-04-11 and filed notice on 2020-05-11. 5,119 Washington residents were affected. 30 days elapsed between awareness and notification. 5 days to identify the breach. 1 days to contain the breach.
- MARYLANDHHS OCRas victim2019-09-17
Magellan Healthcare (MD, Business Associate) reported to HHS on 2019-09-17 a Hacking/IT Incident affecting 55,637 individuals. An employee was the victim of an email phishing scheme compromising ePHI stored in Email systems. Exposed data included names, dates of birth, Social Security numbers, and diagnoses/treatment information. The CE notified HHS, affected individuals, and the media, retrained staff, and offered credit monitoring.