Back to the register

Mississippi Division of Medicaid

ArchivedSubmitted 05/26/2017
State
MS
Covered entity type
Health Plan
Individuals affected
5,220
Business associate present
No
Type of breach
Unauthorized Access/Disclosure
Location of breached information
Email
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

On April 7, 2017 the covered entity (CE), Mississippi Division of Medicaid, discovered that beginning on May 2, 2014, an employee had used WuFoo, an online service, to create and post online forms to the CE’s external website for public use. While these forms were secure on the CE’s and WuFoo’s websites, they were not encrypted when emailed between Wufoo and the CE’s employees. These forms requested protected health information (PHI) from beneficiaries. As the form information was transmitted via unencrypted email across the public internet, the CE was unable to determine whether a third party inappropriately accessed the form information contained in these emails. The CE did not have a Business Associate Agreement (BAA) with WuFoo. The PHI contained in the unsecured forms included: beneficiary or potential applicants’ names, addresses, emails, enrollment dates, Medicaid and/or Medicare identification numbers, social security numbers, phone numbers, clinical information, and health plans. Approximately 4,524 people were affected by the breach. The CE provided breach notification to HHS, affected individuals, and the media, and also provided substitute notice on its website. Following the breach, the CE cancelled its WuFoo account and conducted an audit of all active contracts to ensure proper BAAs. It also revised its purchasing policy and Privacy and Security policies and trained staff on its new policies. Additionally, the CE structured the Privacy Officer position to report directly to the CE’s Executive Director and counseled the employee involved in the breach. OCR obtained assurances that the CE implemented the corrective actions listed above.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.