On December 9, 2024, Health Management Systems of America (HMSA) became aware of unauthorized activity in a single email account due to a spear phishing campaign. The company issued a "Notice of Security Incident" on March 6, 2026, and began notifying affected individuals.
The exposed data varied by person and may have included insurance claims information, employee assistance program information, authorization of services, demographic information, driver’s license numbers, Social Security numbers, chart numbers, login account information, and financial account information. While HMSA began notifying individuals and offered credit monitoring where SSNs were involved, a total count of affected individuals has not been publicly released, though one Massachusetts-related notice indicates one affected individual. The full scope of states affected also remains unclear.
Additional details about the incident, including a comprehensive list of affected individuals and states, may emerge as investigations continue. Official notices to consumers in Massachusetts were sent out on June 16, 2026.