Connecticut officials disclosed a breach in the Medicaid provider portal used by the HUSKY Health program that exposed payment and claims information tied to about 41,000 members. The Connecticut Department of Social Services said its fiscal agent, Gainwell Technologies, detected the intrusion on June 25 after an unauthorized party compromised a provider account, making it the second portal-related incident affecting the program this year.
State officials said the exposed data included names, claim- or payment-related identification numbers, dates and details of medical services, billing information, payment amounts, and in some cases policy and group numbers for non-Medicaid insurance. DSS said there was no indication that electronic health records, Social Security numbers, or financial account details were compromised, and said the attacker appeared to be motivated by financial gain rather than an effort to obtain patient records. Gainwell locked down the portal and added security safeguards, while affected members are being notified by mail and offered free credit monitoring, identity monitoring, and fraud support services.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
After discovering the unauthorized activity, Gainwell locked down the provider portal and implemented additional security safeguards. Connecticut DSS said it was working with its contractor, cybersecurity experts, and law enforcement to investigate and strengthen protections.
Gainwell Technologies detected an intrusion into a Connecticut Medicaid provider account in the HUSKY Health portal on June 25, 2026. The incident exposed claims and payment-related information associated with about 41,000 HUSKY Health members.
In March, an unauthorized user accessed accounts belonging to roughly 22,500 Hartford HealthCare patients in a separate security incident tied to a Medicaid provider portal. The later Connecticut disclosure identified this as an earlier portal-related incident in the same year.
DSS and Gainwell began sending notification letters by postal mail to affected members on Friday and offered free credit monitoring, identity monitoring, and fraud support services. The state also provided a contact number for people who believed they might be affected.
Connecticut's Department of Social Services disclosed that a breach of the Medicaid provider portal exposed payment and claims information tied to roughly 41,000 HUSKY Health members. DSS said the attacker appeared motivated by financial gain and that electronic health records, Social Security numbers, and financial account details were not compromised.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourcemalware.news
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.