Nearly 23,000 patients with the state’s Medicaid program HUSKY may have had their information stolen as part of a criminal breach, according to officials.

On March 25, officials with the Connecticut Department of Social Services said they learned that an “unauthorized third party” had gained access to a small number of Hartford HealthCare’s payment accounts on the HUSKY provider portal website and downloaded files containing patient information. Gainwell Technologies is the account administration service for the HUSKY program, which is administered by the Connecticut Department of Social Services.

Upon becoming aware of the breach, DSS and Gainwell said they promptly launched an investigation with the support of external cybersecurity experts and contacted federal law enforcement. Through the investigation, DSS and Gainwell determined that the unauthorized activity began when the hackers used compromised credentials of Hartford HealthCare employees to access user accounts on the provider portal on March 4.

In response to this incident, DSS and Gainwell said they immediately took steps to secure the provider portal from further activity and terminate the unauthorized third party’s access to the affected portion of the environment. Officials said investigators have confirmed that the attack has been successfully contained and the unauthorized third party no longer has access to the portal.

DSS and Gainwell are also taking steps to implement additional security enhancements designed to mitigate the risk of future incidents.

“External investigators have determined that the unauthorized third party’s activities appeared to be financially motivated, rather than directed at obtaining patient data. Nevertheless, the unauthorized third party gained access to information relating to approximately 22,500 individuals. DSS and Gainwell determined that, while the impacted information varied by individual, in the aggregate this incident involved full name; identification number associated with Hartford HealthCare account or Medicaid claim; dates of medical services; information about services received and how they were billed; payment information, including amounts paid; and information about applicable non-Medicaid health insurance, including policy and group number,” DSS said in a statement.

Officials said the breach did not involve Social Security numbers or financial account information, as that information is not available in the system that was breached.

On May 22, officials with DSS and Gainwell said they began notifying affected individuals through the mail. The notification includes an offer of credit and identity monitoring services and certain fraud support services.

Anyone who believes they may have been impacted is asked to call 1-855-744-4488 for more information.

Stephen Underwood can be reached at sunderwood@courant.com.