Records of more than 17K Medicaid patients in New York compromised by employee

Share this article:

An employee with the New York State Office of the Medicaid Inspector General (OMIG) is suspected of forwarding more than 17,000 records to a personal email account.  

How many victims? 17,743 records of Medicaid recipients.

What type of personal information? Includes, but may not be limited to, first and last name, date of birth, Medicaid client information number and Social Security number.

What happened?  An employee is suspected of accessing the records and emailing them to a personal account.

What was the response? The OMIG notified each potentially compromised individual and sent each person a letter containing instructions on how to monitor credit and protect against identity problems. OMIG has devised tighter controls in its information technology department to limit access to data. All agency employees have been retrained on data security.

Details: An employee is suspected of having made a personal decision, without agency involvement or authorization, to send the records of 17,743 Medicaid recipients to a personal email address. The employee is on administrative leave while the New York State Inspector General's Office conducts an investigation.

Quote: “OMIG expects all employees to act in a professional, ethical manner while in the workplace, and will not tolerate behavior that leads to the release of confidential information,” said Medicaid Inspector General James C. Cox in a release.

Source:, “OMIG Identifies Security Breach: Employee Suspected of Releasing Unauthorized Data,” July 15, 2013.

Share this article:

Next Article in The Data Breach Blog

Sign up to our newsletters


More in The Data Breach Blog

Laptop stolen from Self Regional Healthcare contained patient data

As least 500 patients of Self Regional Healthcare have been notified that their personal information was on a laptop stolen from a Self Regional facility.

Thousands had data on computers stolen from California medical office

Bay Area Pain Medical Associates notified about 2,780 patients that their data was on computers stolen from its California offices.

Subcontractor breach impacts 1,700 in Dominion Resources employee wellness plan

About 1,700 people in the Dominion Resources employee wellness program have been notified that their data was accessed in a breach.