Breach may have exposed some Georgia Medicaid recipients’ health information

Photo courtesy of istock.com.

Date: September 28, 2025

by Ty Tagami | Sep 26, 2025 | Capitol Beat News Service

ATLANTA — The private health information of more than 900 Medicaid recipients in Georgia may have been exposed in July, according to a state contractor.

Gainwell Technologies, the fiscal agent for Medicaid in Georgia, disclosed the incident Friday, saying an unauthorized caller gained access to a reimbursement account and was able to view payment information.

The caller wanted to access payments to providers, the company said through a spokesperson.

“There is no indication that the caller attempted to access individual member accounts; however, the caller was able to view billing statements that included the names, Medicaid member IDs, coverage and payment information for claims and date ranges for when services were provided under Georgia Medicaid,” the company said in a statement.

Social Security numbers were not disclosed in the July 23 incident, the statement said.

Gainwell contracts with the state Department of Community Health. A department spokesperson could not be reached for comment Friday.

Gainwell said it is not aware of any misuse of personal information but is offering free credit monitoring for a year to those affected. The company said it notified 912 Medicaid members whose protected health information might have been disclosed.

Anyone who received a notification letter can call IDX, the identity theft protection service that Gainwell is providing, at 1-833-788-9712.

What to Read Next

The Author

Comment Policy

The Augusta Press encourages and welcomes reader comments; however, we request this be done in a respectful manner, and we retain the discretion to determine which comments violate our comment policy. We also reserve the right to hide, remove and/or not allow your comments to be posted.

The types of comments not allowed on our site include:

  • Threats of harm or violence
  • Profanity, obscenity, or vulgarity, including images of or links to such material
  • Racist comments
  • Victim shaming and/or blaming
  • Name calling and/or personal attacks;
  • Comments whose main purpose are to sell a product or promote commercial websites or services;
  • Comments that infringe on copyrights;
  • Spam comments, such as the same comment posted repeatedly on a profile.