Private Health Data of Thousands of Medicaid Patients in Texas exposed unintentionally

Officials with the state Department of Aging and Disability Services on Thursday revealed that private health data of thousands of Medicaid patients in Texas has been accidentally exposed.

The agency, which is charged with assisting some of the state's most vulnerable people, became aware of the breach in late April.

According to a statement released by the agency, the department removed the problematic website on April 21 when it was advised that the information on the site was publicly accessible on the internet.

It was told that data exposed includes details about names, residences, mailing addresses, birth dates, Social Security and Medicaid numbers, and medical diagnoses and treatment information.

Department spokeswoman Cecilia Cavuto told the Austin American-Statesman that the Web application containing the data had been in use for eight years and was intended for internal use only.

She said there are higher possibilities that the data had been accidentally posted in public when its handling was transferred to another department in last fall.

Cavuto said, "I don't think we have the answer to what exactly caused this breach just yet. It looks like the application was developed without the appropriate security. It was supposed to be an internal application, which points to human error".

The agency said in a statement that so far they have received no evidence confirming that the data has been misused, but still it has arranged for credit monitoring and identity theft restoration services for the affected clients.

CSID Protector, online security provider retained by the state, is sending letters to the affected clients offering its services free of charge to them for one year, it said.