I'm sure they did, and a lot more besides. So what? What is anyone going to do about it? Congress certainly doesn't give a fig.
HIPPA privacy laws are rarely enforced against corporations and government. These laws are meant to suppress whoever they want to. It's baffling how they continue to get away with this until you realize that the United States is a banana republic.
The government's stated remediation for the Palantir transfer was that the data had been shared over a Microsoft Teams chat and was deleted from the chat. That is not a deletion.
According to CMS's security program documentation, Medicare and Medicaid are a covered entities under HIPAA, subject to 60 day notice to affected individuals, reporting to HHS OCR, and notice to media outlets when a breach affects more than 500 residents of a state.
Not to mention this violated a standing court order.
https://security.cms.gov/learn/cms-breach-response-handbook