Press Release

Press Release  Massachusetts residents’ data involved in MOVEit global security incident

Individuals notified and encouraged to take steps to protect their personal information
For immediate release:
8/15/2023
  • Executive Office of Health and Human Services

Media Contact   for Massachusetts residents’ data involved in MOVEit global security incident

Cecille Joan Avila, Media Relations Manager

BOSTONYesterday, UMass Chan Medical School (“UMass Chan”), began notifying more than 134,000 individuals currently or previously enrolled in certain state programs that their personal information was involved in a recent third-party data security incident. This incident was part of a worldwide data security incident involving a file-transfer software program called MOVEit, which has impacted state and federal government agencies, financial services firms, pension funds, and many other types of companies and not-for-profit organizations. No UMass Chan or state systems were compromised in this incident. Impacted individuals have been sent notice by mail and will be contacted by phone, text, and e-mail where possible. Any individual who receives a notice is encouraged to take steps to protect their information, including monitoring their financial account statements and enrolling in free credit monitoring and identity theft protection offered to individuals who had certain sensitive information involved.

UMass Chan provides services to the Executive Office of Health and Human Services (EOHHS) including for MassHealth, the State Supplement Program (SSP), Family Resource Centers (FRCs), the Executive Office of Elder Affairs (EOEA) and Aging Services Access Points (ASAPs). Impacted individuals are a subset of current or recent participants in these programs.

UMass Chan first learned about the MOVEit vulnerability on June 1, 2023 and immediately fixed the vulnerability, contacted law enforcement, launched an investigation and worked to identify the individuals whose information was involved. UMass Chan identified the files that may have been subject to unauthorized acquisition as a result of the MOVEit security flaw.  On July 27, 2023, UMass Chan determined that some of these files contained information pertaining to individuals who received services from EOHHS.

While the information involved in the data security incident varied by person, it included names and one or more of the following:

  • Dates of birth,
  • Mailing addresses,
  • Protected health information, i.e., diagnosis/treatment information, prescription information, provider names, dates of service, claims information, health insurance member ID numbers, and other health insurance related information,
  • Social Security numbers,
  • Financial account information

State Supplement Program (SSP) participants (including recipients, other members of the household and authorized representatives), MassHealth Premium Assistance members, MassHealth Community Case Management participants, and Executive Office of Elder Affairs (EOEA) and Aging Services Access Points (ASAP) home care program consumers were primarily impacted. If you do not participate in one of those programs, it is unlikely your data was exposed.

Beginning on August 15, 2023, individuals whose information was involved will receive letters from the Commonwealth of Massachusetts and UMass Chan. The letter explains what data was impacted for each individual, the actions taken in response to the MOVEit incident and detailed steps that individuals can take to protect their information.

Impacted individuals are encouraged to remain vigilant by reviewing their financial account statements.  If you see charges or activity that you did not authorize, contact your financial institution immediately. Take steps to protect your accounts by contacting your bank, credit union, or financial institution immediately by using the number on the back of your bank card or by visiting in person to notify them of your involvement in this security incident.

UMass Chan is offering free credit monitoring and identity theft protection services to individuals whose Social Security numbers and/or financial information were involved in this incident.

For more information, please visit mass.gov/MOVEitIncident or umassmed.edu. Individuals who receive notification that their data is involved and have further questions may call 855-862-7769, Monday through Friday, from 9:00 a.m. to 5:00 p.m., ET.

 

Media contacts:

Cecille Joan Avila, Executive Office of Health and Human Services

Media Relations Manager

Cell: 857-301-0508

Email: Cecille.J.Avila@mass.gov

 

Sarah Willey, UMass Chan Medical School

Media Relations Manager

Cell: 774-284-0186

Email: sarah.willey@umassmed.edu

###

Media Contact   for Massachusetts residents’ data involved in MOVEit global security incident

  • Executive Office of Health and Human Services 

    The Executive Office of Health and Human Services is comprised of 11 agencies and the MassHealth program. EOHHS seeks to promote the health, resilience, and independence of the nearly one in every three residents of the Commonwealth we serve. Our public health programs touch every community in the Commonwealth.
  • Help Us Improve Mass.gov  with your feedback

    Please do not include personal or contact information.
    Feedback