ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

CMS notifies nearly 950,000 individuals of data breach linked to MOVEit vulnerability

In a press release, the Centers for Medicare & Medicaid Services (CMS) announced that it and its contractor, Wisconsin Physicians Service Insurance Corporation (WPS), are notifying nearly 950,000 individuals whose personal and health information may have been compromised. The breach is connected to a vulnerability in the MOVEit software, a third-party file transfer application used by WPS to provide Medicare administrative services.

 

The breach was discovered between May 27 and May 31, 2023, when unauthorized third parties exploited a vulnerability in MOVEit, allowing access to sensitive information. The data exposed includes personally identifiable information (PII) of Medicare beneficiaries, particularly information collected for managing Medicare claims and conducting CMS audits of healthcare providers. This breach could potentially impact individuals not enrolled in Medicare but who visited providers under CMS audits.

 

WPS informed CMS of the breach on July 8, 2023, and an investigation concluded that no files had been copied. However, in May 2024, new evidence emerged indicating that some files had been exfiltrated before the vulnerability was patched, revealing that personal data had been compromised.

 

Despite the breach, CMS and WPS stated that, to date, there have been no reports of identity theft or fraudulent use of the stolen data. Notifications are being sent to 946,801 affected individuals, with CMS offering further guidance and support.

 

This breach marks the latest in a series of vulnerabilities related to MOVEit software vulnerabilities, which government agencies and regulated industries widely use to handle sensitive information. Notably, a similar breach in 2022 affected approximately 612,000 Medicare beneficiaries through Maximus Federal Services, a CMS contractor, with the potential total impact increasing to 942,000 people.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543