Public Partnerships, the statewide fiscal intermediary for New York’s Consumer Directed Personal Assistance Program, has disclosed that a former, previously terminated network facilitator may have attempted to sell consumer data to another contracted facilitator.
Companies entrusted with processing Medicaid enrollment and identity information for thousands of program participants have a responsibility to protect that data, including after a vendor relationship with the program has ended.
Public Partnerships’s Data Breach Investigation
On June 8, 2026, Public Partnerships became aware of an allegation that a former network facilitator, previously terminated from the Consumer Directed Personal Assistance Program (CDPAP) for failing to meet program integrity requirements, may have offered to sell access to consumer information to another Public Partnerships-contracted facilitator in New York. The facilitator that received the offer refused it and immediately reported the matter to Public Partnerships.
Upon learning of the allegation, Public Partnerships contacted the New York State Department of Health, which referred the matter to the Office of the New York Attorney General for investigation and enforcement. Public Partnerships also contacted the former facilitator directly, informed it that offering to sell CDPAP consumer data is unlawful and a breach of its ongoing contractual obligations, and instructed it to delete all CDPAP-related data still in its possession.
As an additional precaution, Public Partnerships reminded every remaining network facilitator that buying or selling CDPAP participant data is both illegal and a material violation of their contracts, and that any CDPAP-related information in a facilitator’s possession is confidential and protected under state and federal law.
Public Partnerships reported the incident to the U.S. Department of Health and Human Services Office for Civil Rights, which tracks breaches of protected health information affecting 500 or more individuals. That filing lists roughly 12,018 New York residents as potentially affected. According to Public Partnerships, its investigation to date has found no evidence that any consumer data was actually transmitted, sold, or otherwise misused, though notifications to potentially affected consumers have already begun.
Public Partnerships administers the CDPAP program on behalf of the New York State Department of Health, acting as the statewide fiscal intermediary responsible for processing payroll and maintaining enrollment records for consumers who direct their own home care. That role requires the company and its network of contracted facilitators to handle large volumes of Medicaid enrollment and identity information for a vulnerable population, so any lapse in a terminated vendor’s data-handling practices can put a large number of program participants at risk at once, which appears to be what happened here.
Government assistance programs are an especially attractive target for this kind of misconduct because a single facilitator or vendor can hold identity and benefits information for thousands of enrollees at a time. When Medicaid ID numbers, program enrollment details, and other personal identifiers are combined, that data can be used to file fraudulent benefits claims, open unauthorized lines of credit, or impersonate the affected individual with government agencies and financial institutions. Organizations that administer these programs, along with the network of contracted vendors and facilitators they rely on, carry a heightened responsibility to monitor and restrict data access even after a vendor’s relationship with the program has ended.
Incidents involving a terminated vendor are a particular concern in programs like CDPAP that rely on a large, decentralized network of independent facilitators rather than a single in-house workforce. Once a vendor’s contract ends, an organization generally loses direct day-to-day oversight of how that vendor stores or disposes of any data it collected while under contract, which can leave a gap between termination and full data destruction. This incident illustrates why regulators increasingly expect fiscal intermediaries and similar administrators to build stronger contractual and technical safeguards, such as mandatory data-deletion verification and post-termination audits, into their vendor relationships from the outset rather than relying solely on a departing vendor’s word that data has been destroyed.
Home care programs like CDPAP also serve populations, including elderly and disabled individuals, who can be especially vulnerable to follow-up scams after a breach notification goes out. Fraudsters sometimes use news of a real breach to run copycat phishing calls or letters posing as the company, the state Medicaid office, or a credit-monitoring provider, asking recipients to confirm account details or payment information. Consumers who receive an official notice about this incident should independently verify any follow-up communication through the phone numbers Public Partnerships has published rather than a number or link supplied in an unsolicited message.
When Did This Breach Occur?
Public Partnerships states that it first became aware of the allegation on June 8, 2026, after a contracted facilitator refused an offer to purchase consumer data from the previously terminated vendor and reported it. The company publicly disclosed the incident in an August 7, 2026 statement and began the process of notifying affected CDPAP consumers around that time. The exact date on which the former facilitator obtained or attempted to sell the data has not been made public.
What Information Was Breached?
Public Partnerships states that, to the best of its knowledge, the information that may have been affected includes each consumer’s name, address, date of birth, Medicaid ID number, PPL ID number, and enrollment status in New York Medicaid. The company has not disclosed evidence that this information was actually viewed, copied, or sold by the former facilitator, only that it may have been offered for sale to another contracted vendor.
What You Can Do
- Enroll in the complimentary identity protection and credit monitoring services Public Partnerships is offering to potentially affected consumers, available through Experian’s customer care team at 877-890-9332.
- Call the dedicated toll-free number Public Partnerships has set up for this matter, 833-706-5436, Monday through Friday from 8 a.m. to 5 p.m. Eastern time, with any questions.
- Watch for a separate individual notification letter from Public Partnerships with enrollment instructions for the monitoring services.
- Review Medicaid statements and any benefits correspondence for unfamiliar activity.
- Consider placing a fraud alert or credit freeze with the three major credit bureaus if you are concerned about identity theft.
- Report any suspicious activity involving your Medicaid account or personal information to Public Partnerships and to your healthcare provider or financial institution.
File a Data Breach Lawsuit Against Public Partnerships
Consumers who were notified that their personal information may have been exposed by this incident may have legal options, particularly if they experience identity theft, fraudulent account activity, or other harm as a result. An attorney can help evaluate whether Public Partnerships and its network facilitator met their legal obligations to safeguard sensitive Medicaid and personal identification data.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.