CMS Notifying Medicare Beneficiaries of Potential Data Breach
Just FYI in case you get one of these notifications or a new Medicare card.
CMS.gov 06/30/2025 - News Release - CMS Notifies Individuals Potentially Impacted by Data Incident
from the link ~
What Happened?
On May 2, 2025, CMS’ call center began receiving inquiries from beneficiaries who received letters confirming the creation of Medicare.gov accounts they did not initiate. CMS promptly launched an investigation and discovered that malicious actors had fraudulently created new accounts between 2023 and 2025 using valid beneficiary information, including Medicare Beneficiary Identifiers (MBI), coverage start date, last name, date of birth, and zip code.
Once these unauthorized accounts were established, bad actors may have accessed additional beneficiary data, including:
- Provider information
- Mailing address
- Dates of service
- Diagnosis codes
- Services received
- Plan premium details
CMS is not aware of any reports of identity fraud or misuse of the information as a direct result of this activity. Nevertheless, out of an abundance of caution, CMS is taking proactive steps to safeguard beneficiary information.
=============
The news release goes on to say what CMS is doing to correct this -
also from the link~
What Can Beneficiaries Do?
Beneficiaries are encouraged to:
- Review Medicare Summary Notices and Explanation of Benefits for any unfamiliar charges or services.
- Report any suspicious activity to 1-800-MEDICARE (1-800-633-4227) or the Office of Inspector General at oig.hhs.gov/fraud/report-fraud/.
- Obtain free annual credit reports through www.annualcreditreport.com or by calling 1-877-322-8228.
- File reports with local law enforcement and/or the Federal Trade Commission by calling 1-877-IDTHEFT (1-877-438-4338) or online at www.ftc.gov/idtheft if any identity theft concerns arise.
For additional information or questions, beneficiaries can directly contact 1-800-MEDICARE (1-800-633-4227).