Health Management Systems of America
ent_cd06b5bb3988f9b06b5266d2
Disclosures
4
State AG · HHS OCR · 4 jurisdictions
Incidents
—
no linked incident in sample
Max affected reported
4,265
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Health Management Systems of America
- Normalized
- health management systems of america— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- hmsanet.com
Disclosure history (4)newest first
- 🏛️Massachusetts State AGas victim2026-06-01
Health Management Systems, Inc. (HMS) notified Massachusetts residents of a data breach occurring on April 21, 2026. An employee uploaded a photo of their workstation to Facebook, exposing personal information including names, addresses, Social Security Numbers, and claim numbers. HMS investigated, had the post removed, and offered 24 months of identity theft protection via IDX. The incident involved Medicaid benefits administration data.
- 🍁Vermont State AGas victim2026-03-22
Health Management Systems of America (HMSA) reported a data breach to the Vermont Attorney General involving one Vermont resident. On December 9, 2024, HMSA detected unauthorized access to a single email account caused by a spear phishing campaign. The attacker accessed protected health information and Social Security numbers. HMSA secured the account, reset passwords, and engaged forensic investigators. Notification was sent to the affected individual in February 2026, offering 12 months of credit monitoring via Kroll.
- 🏎️Indiana State AGas victim2026-02-09
Health Management Systems of America reported a data breach to the Indiana Attorney General. The breach occurred on 2024-11-11 and was reported on 2026-02-09. 3 Indiana residents were affected. 4,265 individuals affected in total.
- MIHHS OCRas victim2025-10-27
Health Management Systems of America (Michigan) reported to HHS OCR on 2025-10-27 a Hacking/IT Incident affecting 4,213 individuals. Breached information was located in Email. No business associate was present. No further detail is available in the public HHS disclosure.