Maximus, Inc. Data Breach
Maximus Network Server Breach Affects 2.7M Individuals
What happened in the Maximus, Inc. data breach?
The Maximus, Inc. data breach was reported on August 4, 2023 and affected 2,781,617 individuals. The breach type was Hacking/IT Incident involving Network Server. This breach occurred in Virginia. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Maximus, Inc. Breach Details
Maximus, Inc. Data Breach Report
Opening Summary
Maximus, Inc., a major healthcare and human services IT contractor based in Virginia, experienced a significant data breach involving unauthorized access to its network servers. The breach was discovered and reported to the U.S. Department of Health and Human Services on August 4, 2023, affecting approximately 2,781,617 individuals across multiple states. The incident involved a hacking or IT-related intrusion into Maximus's network infrastructure, potentially exposing sensitive protected health information (PHI) and personally identifiable information (PII) maintained on the compromised servers. Maximus operates as a business associate to numerous healthcare entities, meaning the breach has cascading implications for multiple covered entities and their patients.
Company Response and Investigation Timeline
Upon discovery of the unauthorized access to its network servers, Maximus initiated a comprehensive investigation to determine the scope and nature of the breach. The company worked to identify which systems were compromised, what data may have been accessed, and the timeline of unauthorized access. As required under HIPAA Breach Notification Rule (45 CFR §§ 164.400-414), Maximus began the process of notifying affected individuals, covered entities, and regulatory authorities. The submission date of August 4, 2023, indicates this was when the breach was formally reported to HHS, triggering the 60-day notification window for affected individuals. Maximus coordinated with its covered entity clients to ensure proper notification procedures were followed and that individuals received timely and accurate information about the breach.
Specific Details of the Breach
The breach occurred on Maximus's network servers, which typically represent centralized data storage and processing infrastructure. Network server compromises resulting from hacking or IT incidents often involve exploitation of vulnerabilities in network security controls, such as unpatched systems, weak authentication mechanisms, or misconfigured access controls. The fact that this was classified as a "hacking/IT incident" suggests the unauthorized access was achieved through technical means rather than physical theft or loss of devices. Attackers may have exploited known or zero-day vulnerabilities, used credential compromise, or leveraged other network-based attack vectors to gain access to the servers. The scope of 2.7 million affected individuals indicates the breach likely involved multiple databases or systems containing aggregated patient information from numerous healthcare organizations that utilize Maximus's services.
Organizational Context
Maximus, Inc. is one of the largest business process services companies in the United States, specializing in healthcare and human services IT solutions. The company provides critical services including eligibility and enrollment systems, claims processing, customer service platforms, and other healthcare administration functions for state Medicaid programs, Medicare, and other government health programs. With operations spanning multiple states and serving as a business associate to hundreds of healthcare entities, Maximus maintains vast repositories of sensitive patient data. The company's infrastructure supports millions of transactions and stores comprehensive health and demographic information for beneficiaries across numerous state and federal health programs. This centralized role in healthcare administration means that a breach of Maximus's systems has widespread implications across the healthcare ecosystem.
Patient Impact and Notification
Approximately 2,781,617 individuals were affected by this breach, making it one of the larger healthcare data breaches in recent years. These individuals likely include Medicaid beneficiaries, Medicare beneficiaries, and participants in other government health programs across multiple states where Maximus provides administrative services. The affected individuals received notification letters from Maximus and/or the covered entities utilizing Maximus's services, informing them of the breach and the types of information potentially exposed. Notifications were required to be sent without unreasonable delay and no later than 60 days after discovery of the breach, in compliance with HIPAA requirements. The notification process involved coordination between Maximus and its covered entity clients to ensure consistent messaging and to provide affected individuals with appropriate guidance on protective measures and credit monitoring resources.
Industry Context and HIPAA Implications
This breach represents a significant incident within the healthcare IT services sector and underscores the critical importance of strong cybersecurity controls for business associates. Under HIPAA, business associates are required to implement and maintain comprehensive security measures to protect ePHI, including administrative, physical, and technical safeguards. The Security Rule (45 CFR Part 164, Subpart C) mandates specific requirements for access controls, encryption, audit controls, and incident response procedures. When a business associate experiences a breach, covered entities are jointly responsible for notification and may face regulatory scrutiny regarding their business associate agreements and oversight mechanisms. The HHS Office for Civil Rights (OCR) investigates breaches of this magnitude to determine whether appropriate safeguards were in place and whether HIPAA compliance obligations were met. Network server breaches involving hacking represent a persistent threat in healthcare, with attackers increasingly targeting healthcare IT infrastructure due to the high value of health information on the black market. This incident aligns with broader trends of sophisticated cyber attacks against healthcare organizations and their service providers, emphasizing the need for continuous security monitoring, vulnerability management, and incident response capabilities.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Maximus, Inc. Breach
Enroll in complimentary credit monitoring and identity theft protection services offered by Maximus or the affected covered entities. Monitor credit reports from all three bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries. Consider placing a fraud alert or credit freeze with the credit bureaus to prevent unauthorized credit applications.
Review healthcare accounts and explanation of benefits (EOB) statements carefully for unauthorized services, claims, or charges. Contact your health insurance provider and healthcare providers immediately if you identify suspicious activity. Request copies of your medical records to verify accuracy and identify any fraudulent entries.
Monitor financial accounts, including bank accounts and credit card statements, for unauthorized transactions. Set up account alerts with your financial institutions to receive notifications of unusual activity. Consider changing passwords for online banking and healthcare portals to strong, unique passwords.
Be vigilant against phishing emails, text messages, and phone calls claiming to be from healthcare providers, insurance companies, or government agencies. Do not click links or provide personal information in response to unsolicited communications. Verify any requests for information by contacting organizations directly using phone numbers or websites you know to be legitimate.
File a report with the Federal Trade Commission (FTC) at IdentityTheft.gov if you believe your information has been misused. Consider filing a police report if you experience actual fraud or identity theft. Keep detailed records of all fraudulent activity and communications for potential disputes and insurance claims.
Review your Social Security Administration account at ssa.gov and create an account if you haven't already. Monitor for any unauthorized benefits claims or changes to your Social Security record. Consider obtaining your annual free credit report at AnnualCreditReport.com to check for unauthorized accounts.
Contact your state's Attorney General office and the HHS Office for Civil Rights to report concerns about the breach. Request written confirmation of the types of information exposed and the specific notification timeline. Maintain copies of all breach notification letters and communications for your records.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Virginia Breaches
Search all breaches reported in Virginia
Were You Affected?
Patients affected by large healthcare data breaches may be eligible for compensation through class action lawsuits.
Learn about data breach lawsuitsTechnical Notes
Maximus, Inc. Has 2 Reported Breaches
This organization has been involved in multiple reported data breaches.
View full breach history for Maximus, Inc.