Managed Care of North America (MCNA) Data Breach
MCNA Network Server Breach Affects 8.8M Individuals
What happened in the Managed Care of North America (MCNA) data breach?
The Managed Care of North America (MCNA) data breach was reported on May 26, 2023 and affected 8,861,076 individuals. The breach type was Hacking/IT Incident involving Network Server. This breach occurred in Georgia. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Managed Care of North America (MCNA) Breach Details
Managed Care of North America Data Breach Report
Opening Summary
Managed Care of North America (MCNA), a major managed care organization operating in Georgia, experienced a significant data breach involving unauthorized access to its network server infrastructure. The breach was discovered and reported to the U.S. Department of Health and Human Services on May 26, 2023, affecting approximately 8.86 million individuals. This incident represents one of the largest healthcare data breaches in recent years, exposing sensitive protected health information (PHI) and personally identifiable information (PII) to unauthorized parties through a hacking or IT security incident.
Investigation and Response Timeline
Upon discovery of the unauthorized access to its network server, MCNA initiated a comprehensive investigation to determine the scope and nature of the breach. The organization worked to identify which systems had been compromised, what data had been accessed, and the timeline of the unauthorized access. As required under the Health Insurance Portability and Accountability Act (HIPAA) Breach Notification Rule, MCNA notified affected individuals, the HHS Office for Civil Rights, and relevant state authorities. The submission date of May 26, 2023, indicates when the organization formally reported the breach to federal authorities. During this period, MCNA likely engaged forensic investigators and cybersecurity specialists to analyze the breach, contain the threat, and prevent further unauthorized access to its systems.
Technical Details of the Breach
The breach occurred on MCNA's network server infrastructure, which typically serves as a central repository for patient records, claims data, and administrative information across the organization's operations. Network server breaches of this magnitude typically indicate either a sophisticated cyberattack exploiting unpatched vulnerabilities, compromised credentials, or inadequate network segmentation that allowed an attacker to move laterally through systems once initial access was gained. The hacking/IT incident classification suggests the breach resulted from active exploitation rather than physical theft or loss of devices. Given the scale of the breach affecting millions of individuals, the attacker likely gained access to backend database systems or file servers containing consolidated patient information rather than isolated departmental systems. The breach vector may have involved techniques such as SQL injection, credential stuffing, exploitation of known vulnerabilities, or social engineering targeting administrative personnel with system access.
Organizational Context and Operations
Managed Care of North America is a significant player in the managed care industry, providing health insurance and managed care services across multiple states with substantial operations in Georgia. As a managed care organization, MCNA serves as an intermediary between patients, healthcare providers, and insurance carriers, maintaining comprehensive databases of member information, medical histories, claims records, and enrollment data. The organization's network infrastructure supports thousands of employees, contracted providers, and affiliated entities across its service area. The scale of MCNA's operations—affecting 8.86 million individuals—reflects the organization's role as a major health plan administrator serving a substantial portion of the insured population in its operating regions. This breach therefore represents a significant incident affecting a major component of the healthcare delivery and insurance infrastructure.
Impact on Affected Individuals
Approximately 8,861,076 individuals had their personal health information and identifying data potentially exposed through this breach. This population includes current and former members of MCNA health plans, as well as individuals whose information may have been in MCNA's systems through claims processing, provider networks, or other business relationships. The affected individuals span diverse demographics and geographic locations, though the breach was reported in Georgia. Notification of affected individuals occurred following MCNA's discovery and investigation of the breach, with the organization required to provide written notice to each affected person at their last known address or email. The notification timeline would have extended over several weeks or months given the volume of individuals affected and the need to verify contact information and prepare comprehensive notification materials.
Data Exposure and HIPAA Implications
While the specific data elements exposed in this breach were not detailed in the submission, network server breaches of this scope typically involve exposure of multiple categories of protected health information, including names, dates of birth, Social Security numbers, health insurance member IDs, medical record numbers, diagnoses, treatment information, and potentially financial account details. The involvement of a business associate in this breach indicates that MCNA may have been processing or storing information on behalf of covered entities, expanding the scope of affected parties and notification obligations. Under HIPAA regulations, breaches affecting more than 500 residents of a state or jurisdiction must be reported to prominent media outlets, which likely occurred given the scale of this incident. The breach notification requirements mandate that affected individuals receive notice of the breach, the types of information exposed, steps the organization is taking to investigate and prevent recurrence, and recommended actions individuals should take to protect themselves.
Industry Context and Similar Incidents
Large-scale healthcare data breaches involving network infrastructure have become increasingly common as healthcare organizations expand their digital operations and face sophisticated cyber threats. According to HHS breach notification data, hacking and IT incidents represent the leading cause of healthcare data breaches by volume, accounting for the majority of breaches affecting large numbers of individuals. The 8.86 million individuals affected in this MCNA breach places it among the largest healthcare breaches on record, comparable to other major incidents affecting national health plans and large healthcare systems. These breaches underscore the critical importance of strong cybersecurity controls, including network segmentation, encryption of sensitive data, multi-factor authentication, regular security assessments, and incident response planning. Healthcare organizations are required under HIPAA Security Rule standards to implement administrative, physical, and technical safeguards appropriate to the size and complexity of their operations and the sensitivity of the data they maintain.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Managed Care of North America (MCNA) Breach
Place a fraud alert on your credit reports with all three major credit bureaus (Equifax, Experian, TransUnion) by contacting one bureau, which will notify the others. This alerts creditors to verify your identity before opening new accounts in your name.
Consider placing a credit freeze with all three credit bureaus to prevent unauthorized access to your credit reports and restrict new account openings. You can place a freeze for free and lift it when you need to apply for credit.
Monitor your credit reports regularly for suspicious activity by obtaining free annual credit reports from www.annualcreditreport.com and reviewing them for unauthorized accounts or inquiries. Consider using credit monitoring services that alert you to changes in your credit profile.
Monitor your financial accounts and medical records for fraudulent activity, including reviewing bank and credit card statements monthly, checking your explanation of benefits (EOB) statements from your health plan, and requesting copies of your medical records to verify accuracy.
Be cautious of unsolicited communications claiming to be from healthcare providers, insurance companies, or financial institutions. Verify requests independently by contacting organizations directly using phone numbers or websites you know to be legitimate, rather than using contact information provided in suspicious communications.
Consider placing a security freeze on your credit if you have not already done so, which prevents creditors from accessing your credit report without your explicit permission and is more restrictive than a fraud alert.
Document all fraudulent activity discovered and report it to the Federal Trade Commission (FTC) at www.identitytheft.gov, which will create an identity theft report and provide a recovery plan.
Report any fraudulent medical charges or incorrect medical information to your healthcare providers and health insurance company immediately, and request corrections to your medical records if inaccurate information is discovered.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Georgia Breaches
Search all breaches reported in Georgia
Were You Affected?
Patients affected by large healthcare data breaches may be eligible for compensation through class action lawsuits.
Learn about data breach lawsuits