January 26, 2022 Incident: Oklahoma Healthcare Authority
On January 26, 2022, Gainwell and the Oklahoma Health Care Authority discovered that certain individuals’ information within the Medicaid member portal that Gainwell maintains was inadvertently made accessible to a limited number of other Medicaid members, from February 4, 2017 to January 26, 2022. For a small subset of individuals, a limited amount of information, including Medicaid numbers and primary care provider information, was accessible from February 4, 2017 to March 12, 2022. As soon as Gainwell became aware of the issue, it launched an investigation and took measures to restrict any further potential access to this data.
Through its investigation, Gainwell determined that due to an inadvertent configuration issue, when a member moved from one Oklahoma SoonerCare Medicaid member’s account to a different Oklahoma SoonerCare Medicaid member’s account, the individuals within the new account may have had access to certain information within the old account. Gainwell determined that the impacted individuals were limited to this group of members and that any potential access was limited to individuals who were previously members of the impacted individuals’ households and the primary Medicaid subscriber for the new households.
|Agency||Incident Date||Type of Data||Number of Records||More Information|
|Oklahoma Health Care Authority (OHCA)||January, 2022||Personally Identifiable Information (PII)||8,629||Individuals may call toll free to 1-833-774-2183, Monday through Friday 8:00 a.m. and 8:00 p.m., Central Time, to obtain more information about this incident.|