2026 Washington State DSHS — former employee insider breach; 8,600 clients; SSNs exposed
Data compromised
Names, dates of birth, Social Security numbers, DSHS client numbers, and general DSHS program enrollment categories—no evidence diagnoses, test results, treatments, claims, or chart notes were accessed per agency investigation
Technical writeup
Verified insider breach — disclosed June 2026. The Washington Department of Social and Health Services (DSHS) discovered in March 2026 that an employee accessed an internal client data system without authorization and viewed records for reasons unrelated to job duties. DSHS terminated the employee's system access, removed the individual from the department, and investigated access history. Approximately 8,600 individuals are receiving notification letters by mail. Exposed fields include names, dates of birth, Social Security numbers, DSHS client numbers, and general program service categories; DSHS states no specific clinical health information such as diagnoses, test results, treatments, claims, or chart notes was accessed. DSHS is cooperating with law enforcement and reviewing privacy policies. Distinct from credential-based external ransomware incidents.
Root cause
Unauthorized access by a DSHS employee to internal client data systems for non-work purposes; discovered March 2026