In 2023, the Centers for Medicare & Medicaid Services (CMS) reported a data incident affecting its Medicare.gov accounts. The incident, not attributed to Aetna, involved unauthorized access to beneficiary information through fraudulently created online accounts. CMS directly notified affected individuals.
The compromised data types include Medicare Beneficiary Identifiers (MBI), coverage start dates, last names, dates of birth, zip codes, provider information, mailing addresses, dates of service, diagnosis codes, services received, and plan premium details. Approximately 103,000 Medicare beneficiaries were potentially impacted. No Social Security Numbers (SSNs) were confirmed as stolen. The incident refers to data on the CMS Medicare.gov portal, not Aetna's systems.
Details can emerge later, and notices may be delayed.