Vishing trick yields 41,569 patient records at Florida Medicaid plan

A phone scam at Sunshine Health exposed the records of 41,569 people, and Wisconsin billing firm Health Payment Systems disclosed a separate email breach affecting 9,380.

MedRisk Staff
By
2 Min Read

Social engineering delivered another hit to a U.S. health plan in May, when a Sunshine Health employee was talked into releasing plan files to an unknown caller. The voice-phishing attack, detected the same day it happened, compromised protected health information belonging to 41,569 members — records that included names, dates of birth, medical histories, and enrollment details.

For now, the insurer said it has found no signs that the exposed information was put to malicious use. Still, affected members are receiving free credit monitoring and identity-theft protection, and the workforce has been walked through the persuasion tactics phone fraudsters rely on — a reminder that in health plans, the human layer often remains the weakest link.

Separately, a Wisconsin healthcare technology and billing firm took its own incident to the HHS Office for Civil Rights after investigators confirmed that an unauthorized party had reached employee email accounts between June 24 and June 27, 2025, and copied messages. OCR received the notice on July 10, 2026 — more than a year after the initial detection — and the company is now mailing letters to 9,380 affected individuals.

That incident exposed names, addresses, birth dates, IDs, subscription IDs, and subscriber person IDs, plus medical and health insurance information and Social Security numbers for some. The company is providing credit monitoring and says it has tightened security, in a case that highlights how long patients can wait between an email compromise and formal notification.

Share This Article