CMS Notifies 103,000 Medicare Beneficiaries About Unauthorized Account Creation
Approximately 103,000 Medicare beneficiaries are being notified that some of their personal information may have been exposed in a data incident. The HHS Centers for Medicare and Medicaid Services (CMS) was recently alerted that Medicare.gov accounts had been created in individuals’ names without their knowledge. An investigation was launched, which confirmed that a currently unknown threat actor had been using personal information obtained from unknown external sources to fraudulently create Medicare.gov accounts. The CMS said its Medicare call center started receiving calls on May 2, 2025, from beneficiaries who had been sent a letter confirming that an account had been created in their name, when they had not personally created the account. An investigation was launched, which revealed malicious actors had fraudulently created Medicare.gov accounts for approximately 103,000 beneficiaries using valid beneficiary information such as their Medicare beneficiary identifier (MBI), coverage start date, birth date, and zip code. The accounts were fraudulently created between 2023 and...
Esse Health Confirms Almost 264,000 Individuals Affected by April 2025 Cyberattack
Esse Health has confirmed that 263,601 individuals have been affected by its April 2025 cyberattack. Data breaches have also been announced by Health Care and Rehabilitation Services of Southeastern Vermont, Harbor in Ohio, and Mosaic Life Care in Missouri. Esse Health, Missouri Esse Health, an independent physician group healthcare provider with 50 locations in the Greater St. Louis area in Missouri, has recently notified the Maine Attorney General about an April 2025 cyberattack and data breach involving unauthorized access to the personal information of 263,601 individuals, although the breach report submitted to the HHS’ Office for Civil Rights suggests that total only includes the protected health information of 23,671 patients. Esse Health had previously publicly announced the cyberattack, which prevented access to its electronic medical record system, resulting in appointments being cancelled. At the time of the announcement, the investigation and file review were ongoing, so it was unclear how many individuals had been affected. Esse Health has confirmed that the...
DOJ Announces Largest Ever Health Care Fraud Takedown
The U.S. Department of Justice has announced the results of its 2025 National Health Care Fraud Takedown, the largest in its history, eclipsing the previous record of $6 billion with actions to disrupt health care fraud schemes involving more than $14.6 billion in intended losses. Criminal charges have been filed against 324 defendants, including 96 licensed healthcare professionals such as doctors, nurse practitioners, and pharmacists, in 50 federal districts. Across those actions, the government recovered approximately $245 million in cash, cryptocurrency, luxury vehicles, and other assets, while the CMS confirmed that more than $4 billion was prevented from being paid through fraudulent and false claims. In the months leading up to the arrests, the privileges of 205 providers were suspended or revoked. The Health Care Fraud Unit of the Department of Justice Criminal Division’s Fraud Section led the takedown, with assistance provided by the Federal Bureau of Investigation (FBI), Drug Enforcement Agency (DEA), HHS Office of Inspector General (HHS-OIG), and other state and federal...
Healthcare Hacker Facing Extradition to US and Up to 50 Years in Jail
A notorious and prolific hacker alleged to have conducted cyberattacks on more than 40 victims in the United States has been charged in a four-count indictment and is facing extradition to face the charges. Kai West, 25, a British national, is alleged to have operated under the online monikers of IntelBroker and Kyle Northern, and under the name IntelBroker, is alleged to have hacked the networks of a telecommunications company, municipal healthcare provider, an Internet service provider, and more than 40 other U.S. victims. Victims included HPE, Cisco, Nokia, Ford, AMD, Zscaler, and Europol. According to the indictment, recently unsealed by United States Attorney for the Southern District of New York, Jay Clayton, and the Assistant Director in Charge of the New York Field Office of the Federal Bureau of Investigation (FBI), Christopher G. Raia, West’s attacks caused more than $25 million in damages to victims. Over several years, West conducted a hacking campaign for financial gain, mostly attacking companies, stealing their data, and selling the stolen data for profit. According...
FBI; CMS Issue Warning About Fraud and Phishing Attempts on Healthcare Orgs
The Federal Bureau of Investigation (FBI), its Internet Crime Complaint Center (IC3), and the HHS Centers for Medicare & Medicaid Services (CMS) have issued warnings to the healthcare and public health (HPH) sector about ongoing fraud schemes. On Thursday last week, the CMS warned Medicare providers and their suppliers that scammers are impersonating the CMS in phishing requests by fax, requesting copies of medical records and documentation. The phishing attempts claim that medical records and documentation must be provided for a Medicare audit. In the fraud alert, the CMS reminded Medicare providers and their suppliers that the CMS never initiates audits with a request for medical records via fax. If in any doubt about the authenticity of any request claiming to be from the CMS, providers should contact their Medicare Review Coordinator for confirmation that the request is genuine. Any Medicare provider that outsources medical record requests to a third-party vendor should warn their vendor about the fraud scheme. On Friday last week, the FBI and IC3 issued a warning to the...



