Magellan Health, Inc data breach: 5,158 Indiana residents notified
On May 11, 2020, Magellan Health, Inc filed a security-breach notice with the Indiana Attorney General reporting 5,158 Indiana residents affected. That makes it the 18th-largest of the 181 filings on the 2020 register that reported at least 100 Hoosiers. This page shows exactly what the public filing says, what it leaves out, and what to do if you received a notice.
What the official filing says
| Organization, as filed | Magellan Health, Inc |
|---|---|
| Notice filed with the Attorney General | May 11, 2020 |
| Date of the incident, as reported | April 6, 2020 |
| Indiana residents affected | 5,158 |
| Total people affected, all states | 1,650,500 |
| Register year | 2020 |
| Evidence ID | INAG-DB-2020-716705B026 |
| Official source | Indiana Attorney General 2020 register, page 19 (PDF) |
Figures are copied from the register as published. Where the Attorney General's table left a cell empty, this page says “not reported” rather than guessing.
What the filing does not say
A filing is a receipt, not a story. Indiana law requires a business that loses Hoosiers' personal data to notify the Attorney General, and the register records who filed, when, and how many people. It does not record which kinds of data were involved, how the incident happened, or which individuals were affected. The notice letter you received from Magellan Health, Inc is the only document that answers those questions for you.
If you got a letter from Magellan Health, Inc
- Read the letter for the data types. The order of everything else depends on whether it names passwords, Social Security numbers, card numbers, or medical details. Our free breach-letter reader pulls those out on your own device and never uploads the letter.
- Change any password you used with them anywhere else you used it, email account first, and turn on two-step sign-in for email and banking. See my password leaked.
- If a Social Security number was involved, freeze your credit at all three bureaus. It is free and reversible. See freeze your credit and a company lost my SSN.
- Expect the follow-on scam. Criminals read breach news too. A call, text, or email that references this incident and asks you to “verify” anything is the second attack, not help. Paste it into our screenshot checker before you answer.
If Magellan Health, Inc is a health-care provider or insurer you use
Medical records carry the identifiers that outlive a password change: date of birth, insurance member numbers, sometimes a Social Security number. Read your explanation-of-benefits statements for visits you never had, and ask for a copy of your records if anything looks unfamiliar. Our field guide on medical identity theft walks through it in order.
Want someone to go looking for you? Kelsie Hart, Primary Hoosier Agent, runs a bounded personal exposure search for Indiana adults: the identifiers you authorize, checked against lawful breach and credential-exposure sources, written up finding by finding in a private case file within two business days. $39, one time, no subscription.
Other 2020 filings of a similar size
- Aetna — 5,661 Indiana residents
- Gurley-Leep Automotive Management Corporation — 4,639 Indiana residents
- Otis R. Bowen Center for Human Services — 4,572 Indiana residents
- Personal Touch Holding Corp — 3,841 Indiana residents
- Genesis Products, Inc — 3,539 Indiana residents
- Angeion Group — 3,366 Indiana residents
Every 2020 filing with 100 or more Hoosiers →
Questions people ask about this filing
Does this filing mean my information was exposed?
No. It means Magellan Health, Inc told the Indiana Attorney General that an incident affected 5,158 Indiana residents. Only the notice letter you received, or Magellan Health, Inc itself, can tell you whether you were one of them.
What information was involved in the Magellan Health, Inc breach?
The register does not record it. Your notice letter lists the categories involved. Our free breach-letter reader reads that letter on your device and puts the response steps in order.
Where does this information come from?
From the Indiana Attorney General's annual security-breach register, the public list of notices businesses file after losing Hoosiers' personal data. Protect Indiana copies the organization, dates and counts exactly as published and links every entry back to the official PDF. Nothing on this page comes from any other source.
Is there a free way to check whether my email address is in a known breach?
Yes. Have I Been Pwned and Mozilla Monitor check an email address against public breach indexes at no cost. Kelsie's $39 search is for people who want a person to run the identifiers they authorize, read the results, and write down what matters.