Over 100k Medicare Accounts Breached in Latest Hack: Was Yours One?
Letters are going out to 103,000 Medicare beneficiaries who may have been impacted. Here's how to protect your identity and benefits.
Be on the lookout for a letter from Medicare & Medicaid Services (CMS). The government agency that provides medical insurance for more than 67 million Americans 65 and older is notifying Medicare beneficiaries that they may have been part of a data breach in which fake accounts were created in their names.
In a press release issued Monday, CMS said it had identified suspicious activity related to the unauthorized creation of certain beneficiary online accounts using personal information obtained from unknown external sources.
CMS reported that roughly 103,000 beneficiaries might have been affected by the recent data breach. The agency is currently mailing notifications to the individuals, informing them of the incident and outlining steps they can take to protect their personal information.
From just $107.88 $24.99 for Kiplinger Personal Finance
Be a smarter, better informed investor.
Sign up for Kiplinger’s Free Newsletters
Profit and prosper with the best of expert advice on investing, taxes, retirement, personal finance and more - straight to your e-mail.
Profit and prosper with the best of expert advice - straight to your e-mail.
How the Medicare breach happened
On May 2, 2025, CMS’s 1-800-MEDICARE call center began receiving inquiries from beneficiaries regarding letters they received confirming Medicare.gov accounts had been created in their names, the agency said. However, the beneficiaries hadn't created the accounts.
CMS launched an investigation and found malicious actors had fraudulently created new accounts between 2023 and 2025 using valid beneficiary information, including Medicare Beneficiary Identifiers (MBI), coverage start date, last name, date of birth, and zip code.
Once these unauthorized accounts were established, bad actors may have accessed additional beneficiary data, including the following:
-Provider information
-Mailing address
-Dates of service
-Diagnosis codes
-Services received
-Plan premium details
What CMS is doing
CMS said it is not aware of any reports of identity fraud or misuse of the information due to this fraudulent activity, but said out of an abundance of caution, it is taking steps to safeguard beneficiaries' information, including:
-Deactivating all fraudulently created Medicare.gov accounts
-Disabling the ability to create new Medicare.gov accounts from foreign IP addresses to prevent further exploitation
-Continuing to monitor claims data for any suspicious activity and replacing MBIs for affected individuals
-Mailing new Medicare cards with new MBIs to beneficiaries as needed
What you can do
If you receive a letter in the mail from CMS, review your Medicare Summary Notices and Explanation of Benefits and see if you spot any unfamiliar charges or services. Report any suspicious activity to 1-800-MEDICARE (1-800-633-4227) or the Office of Inspector General at oig.hhs.gov/fraud/report-fraud/. It's also important to obtain a free annual credit report through www.annualcreditreport.com or by calling 1-877-322-8228.
If you are a victim of identity theft or fraud, file reports with local law enforcement and/or the Federal Trade Commission by phone at 1-877-IDTHEFT (1-877-438-4338) or online at www.ftc.gov/idtheft if any identity theft concerns arise.
Why hackers go after Medicare
Medicare is a prime target for hackers because of the information they can steal to use for identity theft and financial gain. With stolen Medicare information, bad actors can file fake claims for health care services, medicine and supplies, which cost the government and individuals money.
Medicare information includes a lot of personal identifying data such as names, addresses, birthdates and Social Security numbers. Hackers can use this information to steal a person’s identity, open credit cards in their name, hack into their bank accounts, or take other actions for financial gain. They can even use Medicare information to commit insurance fraud.
The best way to protect your Medicare number is to treat it like a credit card and be careful with whom you share it. Make sure to regularly review your statements, and if you spot any suspicious activity, report it immediately.
Related content
Profit and prosper with the best of Kiplinger's advice on investing, taxes, retirement, personal finance and much more. Delivered daily. Enter your email in the box and click Sign Me Up.

Donna Fuscaldo is the retirement writer at Kiplinger.com. A writer and editor focused on retirement savings, planning, travel and lifestyle, Donna brings over two decades of experience working with publications including AARP, The Wall Street Journal, Forbes, Investopedia and HerMoney.
-
Four Spa Retreats for Well-Heeled RetireesWe hand-picked these U.S. spa retreats for their serenity, amenities and dedication to the comfort of older travelers. All are located in the Continental U.S.
-
Four Military Benefits That Have Helped My FamilyMilitary life can be challenging for servicemembers and their families, but they're offered some significant financial benefits to help cushion the blow.
-
Four Spa Retreats for Well-Heeled RetireesWe hand-picked these U.S. spa retreats for their serenity, amenities and dedication to the comfort of older travelers. All are located in the Continental U.S.
-
Four Military Benefits That Have Helped My FamilyMilitary life can be challenging for servicemembers and their families, but they're offered some significant financial benefits to help cushion the blow.
-
Why More Americans Are Redefining Retirement, Just Like I DidRetirement readiness requires more than just money. You have a lot of decisions to make about what kind of life you want to live and how to make it happen.
-
Eight Spooky Retirement Stats That Will Scare the Bejesus Out of YouThink you have retirement planning down to a science? Consider these scary statistics.
-
Are You Retired? Here's How to Drop the Guilt and Spend Your Nest EggTransitioning from a lifetime of diligent saving to enjoying your wealth in retirement tends to be riddled with guilt, but it doesn't have to be that way.
-
Separating the Pros From the Pretenders: This Is How to Tell if You Have a Great AdviserDo you leave meetings with your financial adviser feeling as though you've been bulldozed into decisions or you're unsure of what you're paying for?
-
I Retired at 60 Two Years Ago With $3.1 Million. My 62-Year-Old Wife Still Works Because She Wants to, but She Resents My Free Time. Help!We asked a psychologist and a mediation expert for advice.
-
Five Downsides of Dividend Investing for Retirees, From a Financial PlannerCan you rely on dividend-paying stocks for retirement income? You'd have to be extremely wealthy — and even then, the downsides could be considerable.