← Washington State DSHS

2026 Washington State DSHS — former employee insider breach; 8,600 clients; SSNs exposed

2026 8.6K records affected Share on X

Data compromised

Names, dates of birth, Social Security numbers, DSHS client numbers, and general DSHS program enrollment categories—no evidence diagnoses, test results, treatments, claims, or chart notes were accessed per agency investigation

Technical writeup

Verified insider breach — disclosed June 2026. The Washington Department of Social and Health Services (DSHS) discovered in March 2026 that an employee accessed an internal client data system without authorization and viewed records for reasons unrelated to job duties. DSHS terminated the employee's system access, removed the individual from the department, and investigated access history. Approximately 8,600 individuals are receiving notification letters by mail. Exposed fields include names, dates of birth, Social Security numbers, DSHS client numbers, and general program service categories; DSHS states no specific clinical health information such as diagnoses, test results, treatments, claims, or chart notes was accessed. DSHS is cooperating with law enforcement and reviewing privacy policies. Distinct from credential-based external ransomware incidents.

Root cause

Unauthorized access by a DSHS employee to internal client data systems for non-work purposes; discovered March 2026

References