[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f31cSKjB7hvLtf_sRjMLJBT7z_BuWRm0DTcvM7Rb7jIY":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":17,"dataClasses":18,"description":32,"source":33,"isVerified":4,"isSpamList":34,"isSensitive":4,"severity":35,"processingStatus":36,"logoUrl":37,"contentUpdatedAt":16,"hasEnglishDescription":4},"6a66ded3ee8a936a6cc94292","CMSMedicareGovAccounts2025","CMS Medicare.gov Accounts 2025 Data Breach","cms-medicare-gov-accounts-2025","cms.gov",{"name":12,"sector":13,"country":14,"website":10},"Centers for Medicare & Medicaid Services","Government","United States","2025-05-02T00:00:00.000Z","2026-07-27T04:30:11.286Z",107154,[19,20,21,22,23,24,25,26,27,28,29,30,31],"Personal information","Protected health information","Medicare Beneficiary Identifiers","Coverage start dates","Names","Dates of birth","ZIP codes","Provider information","Mailing addresses","Dates of service","Diagnosis codes","Services received","Plan premium details","\u003Cp>\u003Cstrong>The CMS Medicare.gov accounts 2025 data breach\u003C\u002Fstrong> involved unknown malicious actors using valid Medicare information obtained from external sources to create unauthorized online accounts. The Centers for Medicare &amp; Medicaid Services detected the activity through call-center inquiries on May 2, 2025. The current HHS OCR record reports a scope of 107,154 Medicare beneficiaries.\u003C\u002Fp>\n\u003Cp>The actors used Medicare Beneficiary Identifiers, coverage start dates, last names, dates of birth, and ZIP codes to create fraudulent accounts. Once established, those accounts may have exposed provider information, mailing addresses, dates of service, diagnosis codes, services received, and plan premium details. LeakData imported no beneficiary records, and importedRecordCount is zero.\u003C\u002Fp>\n\u003Ch2>How Was the CMS Medicare.gov Breach Confirmed?\u003C\u002Fh2>\n\u003Cp>The primary evidence is CMS's official June 30, 2025 press release and sample notification letter. The agency says actors used data obtained from an unknown external source to create fraudulent Medicare.gov accounts and may then have accessed additional beneficiary information. This is an account-fraud incident separate from the 2023 CMS contractor MOVEit breach.\u003C\u002Fp>\n\u003Cp>The HHS OCR row classifies the organization as a Health Plan, the event as a Hacking\u002FIT Incident, and the information location as Network Server; it lists 107,154 people. Healthcare Finance News independently reviewed the CMS statement and reported how the fraudulent accounts operated, the identity fields used, and the agency's response. The sources align on method, timing, and data scope.\u003C\u002Fp>\n\u003Ch2>How Were the Unauthorized Accounts Discovered?\u003C\u002Fh2>\n\u003Cp>On May 2, 2025, the CMS 1-800-MEDICARE call center began receiving inquiries from beneficiaries who had received confirmation letters for Medicare.gov accounts they did not create. The agency promptly opened an investigation and found that malicious actors had used valid beneficiary information to create new accounts between 2023 and 2025.\u003C\u002Fp>\n\u003Cp>The public statement does not identify a single first attack day and says fraudulent creation occurred across the 2023-2025 period. The breachDate field therefore uses May 2, 2025, when CMS confirmed detection, rather than inventing an earlier access date. June 30 on the HHS row is the public report date and is not interpreted as the incident's beginning.\u003C\u002Fp>\n\u003Ch2>What Medicare Information Was Affected?\u003C\u002Fh2>\n\u003Cp>The fields used to create accounts were Medicare Beneficiary Identifiers, Medicare coverage start dates, last names, dates of birth, and ZIP codes. Those inputs came from unknown sources outside CMS, but their valid combination allowed the actors to establish unauthorized identities inside Medicare.gov.\u003C\u002Fp>\n\u003Cp>After the accounts were created, the actors may also have viewed provider information, mailing addresses, dates of service, diagnosis codes, services received, and plan premium details. dataClasses records both stages but does not add passwords, Social Security numbers, payment cards, or bank accounts not disclosed by CMS. It also does not assume that every field applied to all 107,154 people.\u003C\u002Fp>\n\u003Ch2>How Is the 107,154-Person Scope Used?\u003C\u002Fh2>\n\u003Cp>The initial CMS announcement rounded the affected population to approximately 103,000 beneficiaries. The subsequently updated HHS OCR public row provides the exact value of 107,154; pwnCount and totalRecords use that current regulatory figure. The earlier approximate number is not added or treated as a separate event.\u003C\u002Fp>\n\u003Cp>This figure is not a count of fraudulent accounts, viewed pages, claims, or data fields; it represents people in the breach-notification population. A single beneficiary account may contain multiple health, plan, and service details. LeakData records 107,154 only as the affected population and does not invent an unknown account count or subgroup totals for each data class.\u003C\u002Fp>\n\u003Ch2>What Protective Steps Did CMS Take?\u003C\u002Fh2>\n\u003Cp>CMS deactivated all fraudulently created accounts and disabled creation of new Medicare.gov accounts from foreign IP addresses. It continued monitoring claims data for suspicious activity, replaced Medicare Beneficiary Identifiers for affected people, and mailed new Medicare cards carrying new identifiers when needed.\u003C\u002Fp>\n\u003Cp>When the official statement was issued, CMS knew of no reports of identity fraud or direct misuse resulting from the activity. The agency nevertheless applied the changes as precautions. People receiving replacement cards should stop using the former Medicare number and ensure that their healthcare providers record the new identifier.\u003C\u002Fp>\n\u003Ch2>What Should Affected Beneficiaries Do?\u003C\u002Fh2>\n\u003Cp>Notice recipients should regularly review Medicare Summary Notices and insurance explanations of benefits for unfamiliar charges, doctors, diagnoses, or services. Suspicious activity can be reported to 1-800-MEDICARE or the HHS Office of Inspector General. If a replacement card arrived, claims using the former Medicare number deserve particular scrutiny.\u003C\u002Fp>\n\u003Cp>Links in unexpected account-verification, card-renewal, or payment messages using CMS or Medicare branding should not be opened directly; contact should begin at Medicare.gov or the official number printed on the card. Free credit reports can also be monitored for identity-abuse indicators. LeakData hosts no beneficiary data; it provides verified incident metadata and practical follow-up guidance.\u003C\u002Fp>","Official CMS notice confirming fraudulent Medicare.gov account creation",false,"High","completed","\u002Fuploads\u002Flogo\u002Fcms_gov.svg"]