{"id":347520,"date":"2025-12-14T03:07:28","date_gmt":"2025-12-14T03:07:28","guid":{"rendered":"https:\/\/www.newsbeep.com\/us\/347520\/"},"modified":"2025-12-14T03:07:28","modified_gmt":"2025-12-14T03:07:28","slug":"medicaid-firm-struggles-to-block-data-from-india-workers-1","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/us\/347520\/","title":{"rendered":"Medicaid Firm Struggles to Block Data From India Workers (1)"},"content":{"rendered":"<p>The largest processor of Medicaid claims is leaving Americans\u2019 personal health and identifiable information vulnerable to access by its overseas workers, as a push to send more operations to India clashes with its contractual obligations to keep that data from being seen outside the US.<\/p>\n<p>Interviews with 15 current and former Gainwell Technologies employees over several months, backed by a review of internal communications, emails and records of individual meetings, show its systems can\u2019t always prevent protected data from being viewed by workers in India.<\/p>\n<p>Personal health information has been visible during troubleshooting meetings, group chats and through a process called \u201cknowledge transfer\u2019\u2019 \u2014 online sessions where US employees train the India workers who may eventually replace them.<\/p>\n<p>\u201cMedicaid and claims tied to U.S. citizens can be accessed by offshore contractors. It is not just a security risk \u2013 it is a breach of trust and a direct conflict with the commitments Gainwell has made to state agencies,\u201d said Bob Colson, a former Gainwell applications manager who said he resigned in August over what he called ethical concerns with the company\u2019s overseas data practices.<\/p>\n<p>\u201cThere is a troubling disconnect between policy and practice.\u201d<\/p>\n<p>Gainwell, based in Irving, Texas, has more than 2,600 people working from India, according to current employees -\u2014 more than double the number mentioned two years ago in its 2023 Diversity, Equity and Inclusion report. It provides Medicaid processing work that touches about 70 million of the approximately 80 million enrollees in the federal-state insurance program for low-income and disabled Americans.<\/p>\n<p>US employees, who have long legally shared identifiable patient and provider data with each other, now interact daily with newer co-workers in India who, under Gainwell policy and its contracts with more than two dozen states, aren\u2019t supposed to see any of it.<\/p>\n<p>The issue, some employees said in interviews, is that it\u2019s difficult if not impossible for some of the jobs in India to be done without at least some access to identifying information. That becomes particularly problematic during training and troubleshooting meetings because the live, unredacted data US workers are seeing sometimes is also visible to their India colleagues, the workers said.<\/p>\n<p>Gainwell declined repeated requests for an interview, but in written responses to questions it strongly disputed claims by Colson and other current and former employees that systems containing protected health information (PHI) and personally identifying information (PII) can be seen or accessed by workers in India.<\/p>\n<p>\u201cSafeguarding client data is Gainwell\u2019s utmost priority. Client data is not being accessed by anyone outside the United States who should not have access,\u201d the company said in a statement issued through the New York public relations firm Heller.<\/p>\n<p>Risk of Theft<\/p>\n<p>Gainwell says its security systems are state-of-the-art and \u201censure databases containing PHI cannot be accessed by people who should not access them,\u201d according to a letter from its law firm, Meier Watkins Phillips Pusch. \u201cGainwell steadfastly abides by all provisions limiting data storage and access to the U.S.\u201d<\/p>\n<p>Protected health information and personally identifying information is particularly appealing to fraudsters and black-market thieves, the HIPPAVault, a cyber-security firm specializing in protecting patient data, wrote <a href=\"https:\/\/www.hipaavault.com\/resources\/dark-web-healthcare-phi\/\" rel=\"nofollow noopener\" target=\"_blank\">in a March blog post<\/a>.<\/p>\n<p>\u201cWhat makes PHI so potent &#8230;. is its authenticity. Medical records include verified data points that financial institutions trust\u2014making it easier for fraudsters to bypass traditional safeguards.\u201d<\/p>\n<p>Federal law doesn\u2019t prohibit personal health data from being handled outside the US. But nearly all of Gainwell\u2019s state contracts prohibit storing, viewing or accessing any identifying information outside US borders. Some, including New York and Colorado, have denied repeated requests by Gainwell to do state Medicaid work in India.<\/p>\n<p>Gainwell has declined to say which states, if any, allow it to handle US patient data outside of the US, saying it can\u2019t discuss any client relationships.<\/p>\n<p>De-Identifying Data<\/p>\n<p>Gainwell is the primary Medicaid information systems vendor in 32 states and territories after a series of mergers and acquisitions that gave it dominance in the market. It has 10,600 employees worldwide, according to Forbes.<\/p>\n<p>Its parent company is carrying $5.7 billion in debt as a result of those deals, according to data compiled by Bloomberg. That prompted at least $250 million in spending cuts that led to jobs being slashed in the US and contributed to its push to shift more jobs to India, according to a July <a href=\"https:\/\/www.spglobal.com\/ratings\/en\/regulatory\/article\/-\/view\/type\/HTML\/id\/3411237\" title=\"S&amp;P report on Gainwell\" rel=\"nofollow noopener\" target=\"_blank\">report<\/a>by Standard and Poor\u2019s. The company has put its annual revenue at more than $2 billion. <\/p>\n<p>Michelli Kelly, who served as a Gainwell director of engineering until October, said she and members of her team were directly pressured by Vice President Eshwar Muddasani to allow teams of subcontractors and engineers in India access to unredacted US health care data. <\/p>\n<p>She said she refused. She said she was laid off in October after weeks of disagreements over data practices; the company said she was laid off in November as part of a reduction in force.<\/p>\n<p>\u201cEshwar told me to give India access to environments where they would be able to see and access live patient data. It happened a lot, and I was like a mocking bird repeating over and over that it was PHI, and I wouldn\u2019t do it. I wasn\u2019t going to break our contracts,\u201d Kelly said. \u201cTeams of developers in India, including subcontractors that Eshwar hired, were seeing live, actual data. I am positive of that.\u201d<\/p>\n<p>\u201cDe-identifying data is expensive and time consuming, and Gainwell was in too much of a hurry to get the India workers up and running,\u201d Kelly said.<\/p>\n<p>Muddasani denied Kelly\u2019s account. \u201cI want to make it clear that it is not true\u2014I\u2019ve never suggested that an offshore employee or offshore contractor should access PHI or PII,\u201d he said in an email.<\/p>\n<p>Yvonne Bell, a former Gainwell senior professional software engineer, said that in August she identified and removed 20 India-based engineers who\u2019d been improperly given access to critical Gainwell systems and folders servicing the California Medicaid account. Those systems allowed remote access to full, unredacted patient and provider information that included tax identification numbers, dates of birth, Social Security numbers and other protected information, she said.<\/p>\n<p>Bell, who said she was laid off on Oct. 14, worked on the California account for 14 years, including for companies and contracts acquired by Gainwell.<\/p>\n<p>\u201cI know the California contract, what is allowed, what is right and what isn\u2019t. California doesn\u2019t allow any offshore access, but Gainwell is using engineers in India to do work on MMIS systems, CRM, architecture, data dictionaries,\u201d Bell said. \u201cIt is wrong, and I complained over and over, but the company did nothing.\u201d<\/p>\n<p>On Aug. 11, she sent an email to members of the California team outlining some of her concerns. She also said she told her team and Gainwell executives that the India access wasn\u2019t allowed under the California contract. She said she was ignored.<\/p>\n<p>\u201cNothing happened . . . Under our ethics policy, there was supposed to be an investigation, but nobody investigated or even talked to me,\u201d Bell said, adding that she followed up multiple times.<\/p>\n<p>Gainwell disputed Bell\u2019s account.<\/p>\n<p>\u201cTo be crystal clear: the individuals working on the California account Ms. Bell identified and removed were all U.S.-based, and no PHI\/PII connected to the California account was accessible offshore,\u201d a company spokesman wrote in a statement. \u201cShe raised concerns to her manager, the concerns were thoroughly investigated, and the investigation conclusively determined there was no improper sharing of PHI or PII.\u201d<\/p>\n<p>Bell provided Bloomberg Law with the names of three of the employees whose access she said she blocked. Two were based in Surya Wave, Bangalore, and one was based in Chennai, India, according to a database of Gainwell employees obtained by Bloomberg Law independently of Bell.<\/p>\n<p>Knowledge Transfers<\/p>\n<p>Although the data used in knowledge transfers and troubleshooting sessions is supposed to be de-identified, three current and three former employees said that actual patient names and histories are sometimes exposed \u2014 even if accidentally \u2014 during training. The demands of training all the new workers sometimes outpaces the ability of engineers to de-identify the data needed for those sessions, Kelly and others said.<\/p>\n<p>Gainwell said these current and former employees aren\u2019t telling the truth, and that its systems are built to overcome human error.<\/p>\n<p>\u201cAccess is governed by role-based access control, ensuring users can only reach the systems, tools and data required for their specific roles. Geo-fencing policies further strengthen security by limiting access to authorized regions and flagging anomalous connection attempts,\u201d Stacey Smith, Gainwell\u2019s chief information security officer, said in a statement.<\/p>\n<p>Andrew Saxe, a former Gainwell executive who left the company four years ago, said that he has no knowledge of Gainwell\u2019s current activities, but cautioned that the potential availability of \u201cPHI out-of-country by any vendor would be reckless.\u201d Saxe said protecting private patient information, enforcing HIPAA and complying with state contracts trumped everything when he was at the company.<\/p>\n<p>If this is happening, \u201chaving foreigners handle any part of the (Medicaid Management Information System) that contains the confidential information of American patients and providers violates the trust between the citizenry and government,\u201d Saxe said. \u201cPublic sector contracts come with important legal and ethical obligations that transcend profit.\u201d<\/p>\n<p>Nevada Chat<\/p>\n<p>Gainwell had finally gone live with a major software upgrade for Nevada Medicaid, months behind schedule and littered with bugs. Engineers on two continents spent days working on fixes. <\/p>\n<p>Then, shortly before 9 a.m. on Aug. 4, protected health information and member ID numbers popped up on computer screens during an internal chat session.<\/p>\n<p>\u201cWe are adding in PHI .. please be aware that we have Offshore people in this chat,\u201d a US employee wrote in the troubleshooting chat, which was shared with Bloomberg Law. \u201cShould there be offshore people in a production support channel?\u201d another wrote. Another added, \u201cWe are checking and removing offshore members from this chat.\u201d<\/p>\n<p>By the time the chat session ended about 14 minutes later, at least four Gainwell India-based workers listed as being on the chat had been removed.<\/p>\n<p>\u201cI have went through and removed anyone I know is offshore,\u201d an employee wrote, according to copies of the chat meeting.<\/p>\n<p>Gainwell\u2019s law firm wrote that \u201cNo India-based workers saw or received the PHI\u201d on the Nevada chat. It praised the employees for intervening so quickly.<\/p>\n<p>\u201cOne employee shared PII in the chat, and another employee almost immediately realized that four (not six) India-based workers may have access to the chat the next day,\u201d the attorneys wrote. Gainwell said it followed up with the India workers and received assurances they didn\u2019t see the data. None of the four responded to Bloomberg Law\u2019s emailed requests for comment.<\/p>\n<p>The statement said that the India-based workers \u201cwere not in the chat at the time,\u201d adding, \u201cit was nighttime in India.\u201d<\/p>\n<p>Many engineers in India work overnight shifts to overlap with US healthcare hours, according to the company\u2019s job postings and interviews with employees. <\/p>\n<p>A spokesman for the Nevada Health Authority said Gainwell has assured the state that no patient information is being accessed or viewed outside the US.<\/p>\n<p>\u201cAccess to Nevada Medicaid PHI or other sensitive data by offshore personnel is strictly prohibited under our agreement with Gainwell,\u201d the authority wrote in a statement to Bloomberg Law, adding the emphasis in bold.<\/p>\n<p>Gainwell said its systems are secure and protected to make sure no patient information is accessed by anyone outside the US.<\/p>\n<p>\u201cThe company\u2019s infrastructure is further protected through network segmentation, for example, by isolating engineering, non-production, and production environments from each other to minimize lateral movement across environments and contain potential threats.\u201d<\/p>\n<p>Data Migration <\/p>\n<p>Three months after the Nevada chat, two senior Gainwell engineers, one based in Bangalore and the other in Chennai, India, organized a live Teams meeting with its US colleagues for a \u201cdata migration clarification discussion,\u201d according to records of the meeting viewed by Bloomberg Law. No data was shared or viewable during that Teams meeting.<\/p>\n<p>The Nov. 21 meeting took place at 10:30 East Coast time, and specifically noted that the engineers organizing the Teams meeting were working overnight hours from India.<\/p>\n<p>Gainwell said in a statement that \u201cclient data is not being accessed by anyone outside the United States who should not have access. In regards to this specific call, it was a routine call and did not include any transfer of PHI or PII.\u201d<\/p>\n<p>One of the engineers listed on that morning\u2019s Teams call was also one of the four India workers named on the August Teams chat in Nevada.<\/p>\n<p>All were listed as having accepted the Teams invitation and being present during the data migration discussion.<\/p>\n<p>Policy Changes<\/p>\n<p>Two months ago, Gainwell announced changes to its data policies.<\/p>\n<p>\u201cDirect access to the production environment will be removed and granted only by exception,\u201d Chief Transformation Officer Jaffry Mohammed wrote to staff on Oct. 1, referring to live, unredacted data. The restrictions cover all employees, and coincided with a new five-person \u201cChange Advisory Board\u201d that creates new restrictions on what systems US-based developers can access or change and limits the time they will have access, according to three employees and internal notices shared with Bloomberg Law.<\/p>\n<p> <a href=\"https:\/\/aboutblaw.com\/bkna\" target=\"_blank\" rel=\"nofollow noopener\"> <img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/us\/wp-content\/uploads\/2025\/12\/1765681648_248_\" data-alignment=\"center\" data-size=\"embedded\"\/> <\/a> <\/p>\n<p>\u201cGainwell routinely updates employees on best security practices,\u201d the company said. <\/p>\n<p>\u201cGainwell removed access to the production environments and then reinstated access for only the most senior members of the staff, to limit the number of people migrating final bug fixes and code to the live program used by customers,\u201d the company\u2019s lawyers wrote. \u201cThe change was made to prevent outages and enhance system stability.\u201d<\/p>\n<p>The Replacements<\/p>\n<p>Gainwell is increasingly relying on India-based subcontractors to provide engineering and technical support for its state Medicaid contracts. The company has as many as 400 sub-contractors working for India-based technology companies, Gainwell employees said.<\/p>\n<p>One of those, Infinite Computer Solutions, owes $2.3 million in US taxes, according to a lien filed by the federal government in July. It remains unpaid, according to Maryland state court records.  <\/p>\n<p>Infinite Computer Chairman Sanjay Govil didn\u2019t respond to emails or messages left in person at the company\u2019s Rockville, Md., address. More than a dozen phone calls placed to its Maryland office were sent to voicemail.<\/p>\n<p>Gainwell declined to answer questions about its relationship with Infinite.<\/p>\n<p>Gainwell has transferred more than 200 of its workers to Infinite, in a process employees referred to as rebadging, where many perform the same US Medicaid work they always did, according to five current and former employees.<\/p>\n<p>A former Gainwell testing supervisor for the Louisiana Medicaid contract, who was transferred to Infinite earlier this year after 20 years at Gainwell, said much of that work involves training sessions with dozens of Infinite\u2019s India workers assigned to state Medicaid contracts.<\/p>\n<p>She said she was laid off by Infinite in October after training the India-based workers for about three months, and weeks after she complained to her Infinite Computer managers that actual patient data was being shared during some of those sessions. The supervisor asked not to be named because of unresolved issues with Infinite over payment of health and retirement benefits.<\/p>\n<p>David Plokhooy, a former systems operations manager for multiple Gainwell state accounts, said he personally was informed by his staff of instances in recent months where unredacted data had been inadvertently shown to India-based workers. Plokhooy was laid off in October, as part of Gainwell\u2019s cost-cutting measures.<\/p>\n<p>In late June or early July, \u201c(I got) email from an employee who accidentally displayed PHI\/PII during a knowledge transfer and he reported it to me immediately. I escalated the issue to senior management, it was then escalated to the Chief Security Officer,\u201d Plokhooy said in an interview.<\/p>\n<p>\u201cHe reviewed the incident and responded that the India workers are Gainwell employees and as such there is no restriction on sharing PHI\/PII with them.\u201d<\/p>\n<p>Gainwell said that never happened.<\/p>\n<p>\u201cGainwell investigates and addresses any concerns it receives about alleged improper PHI sharing,\u201d the company said in a statement. <\/p>\n<p>Colson, the former Gainwell applications manager who resigned in August over what he called ethical concerns with Gainwell\u2019s data practices, said he believes the company\u2019s legal team is trying to do the right thing, but isn\u2019t being listened to.<\/p>\n<p>\u201cI do not blame the legal, contracts and compliance teams. They are good people and mean well,\u201d he said. \u201cIt is the IT leadership that is pressing this offshore access and side-stepping the rules.\u201d<\/p>\n<p>The company said Colson, who joined Gainwell in 2019 and served as an applications manager and ServiceNow platform owner, \u201craised limited questions about a system during its development phase.\u201d<\/p>\n<p>\u201cThe questions raised were all fully addressed during implementation through controls outside of Mr. Colson\u2019s purview,\u201d the company said in a statement. \u201cDue to the scope of his role, he was unaware of subsequent changes and the final system design.\u201d<\/p>\n<p>Laurie Kelly, a former program analyst at Gainwell who retired earlier this year after working on contracts for Louisiana and New Jersey, said it would be impossible to do her job without access to complete US patient information. \u201cI absolutely needed access to PHI, social security numbers, everything, but they still had me training people in India to take my place,\u201d Kelly said.<\/p>\n<p>Gainwell didn\u2019t respond to Laurie Kelly\u2019s account.<\/p>\n<p>Operating Out of Sight<\/p>\n<p>Some states, including Nevada, allow Gainwell to do database work in India using de-identified data and testing that does not allow live patient data. Gainwell has more than three dozen workers in India assigned to its Nevada contract, according to the company\u2019s internal staffing records reviewed by Bloomberg Law.<\/p>\n<p>Three India-based workers assigned to the Nevada Medicaid contract are listed as doing engineering for provider prior authorization, two are listed under claims and five are categorized in the company\u2019s organization chart as doing \u201cdata warehouse\u201d work, without elaborating on what that entails, according to a Gainwell document obtained by Bloomberg Law. Gainwell employees in four states said those assignments would almost certainly have required access to at least some identifiable patient data, including prescription and medical histories.<\/p>\n<p>Gainwell, in its written responses, said, \u201cAll Medicaid prior authorization review and claims processing work involving personal health information is done in the United States.\u201d<\/p>\n<p>\u201cIt\u2019s a bright line rule at Gainwell: no claims work is performed in India.\u201d<\/p>\n<p>Five workers told Bloomberg Law they have been ordered to never discuss the India operations with any state Medicaid officials.<\/p>\n<p>\u201cWe were told not to discuss anything with the states, not to tell them about anything,\u201d said Laurie Kelly, the former senior program analyst.<\/p>\n<p>Creation of HIPAA<\/p>\n<p>As more patient health data was stored digitally, Congress created the Health Insurance Portability and Accountability Act &#8211; HIPAA &#8211; in the 1990s to help protect private patient data, and protect the healthcare and insurance companies that handled that data. Under the law, any employee who handles patient information must undergo extensive training, which is renewed each year.<\/p>\n<p>\u201cWithout HIPAA there would be no requirement for healthcare organizations to safeguard data \u2013 and no repercussions if they failed to do so \u2013 potentially resulting in widespread medical identity theft,\u201d according to the HIPAA journal, a medical trade publication.<\/p>\n<p>HIPAA, and state contracts, are designed specifically to provide the ability to protect information and enforce state and federal laws, health care experts said. Keeping that data under US control \u2014 and within the US justice system if things go wrong \u2014 is crucial to protecting data.<\/p>\n<p>Jeffrey Grant, a former deputy director for operations at the federal Centers for Medicare &amp; Medicaid Services, said the ability of any state to conduct investigations depends in large part on making sure data remains in the US. Grant led federal investigations and enforcement actions \u2014 including one unrelated to Gainwell alleging improper access to and misuse of personal health information from India \u2014 until leaving the CMS earlier this year.<\/p>\n<p>\u201cAn employee in the US can steal data and do nefarious things with it just as an employee in India can,\u201d Grant said. \u201cBut the reason every state won\u2019t let data go overseas is because they are no longer subject to our criminal and civil law. Good luck convincing somebody in the India government to get that data back and go after anyone.<\/p>\n<p>\u201cYou want to make sure your data is in the US so you can have legal recourse,\u201d Grant said. \u201cAmerican citizens need to know that when the law is violated the government has the authority and the resources to go after the people who did it.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"The largest processor of Medicaid claims is leaving Americans\u2019 personal health and identifiable information vulnerable to access by&hellip;\n","protected":false},"author":2,"featured_media":347521,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[59],"tags":[7761,7257,173393,104964,173392,68165,97,252,173395,253,173394,2539,1341,11324,26022,79591],"class_list":["post-347520","post","type-post","status-publish","format-standard","has-post-thumbnail","category-health-care","tag-acquisitions","tag-cybersecurity","tag-data-protection-non-u-s","tag-diversity-and-inclusion","tag-employment-abroad","tag-enterprise-risk-management","tag-health","tag-health-care","tag-health-data-privacy","tag-healthcare","tag-job-training","tag-layoffs","tag-medicaid","tag-medical-records","tag-mergers","tag-reductions-in-force"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/347520","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/comments?post=347520"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/347520\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media\/347521"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media?parent=347520"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/categories?post=347520"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/tags?post=347520"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}