[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fBTHgwoUBaRxRsCCdFAi-VNJdyRJA1JYKYuy3lhVQArw":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":17,"dataClasses":18,"description":37,"source":38,"isVerified":4,"isSpamList":39,"isSensitive":4,"severity":40,"processingStatus":41,"logoUrl":42,"contentUpdatedAt":16,"hasEnglishDescription":4},"6a66eb8952bd0ba1d9b6c58c","AitkinCountyHealthHumanServices2026","Aitkin County Health and Human Services 2026 Data Breach","aitkin-county-health-human-services-2026","co.aitkin.mn.us",{"name":12,"sector":13,"country":14,"website":10},"Aitkin County Health and Human Services","Government","United States","2026-04-07T00:00:00.000Z","2026-07-27T05:24:25.891Z",83114,[19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36],"Personal information","Protected health information","Names","Addresses","Dates of birth","Social Security numbers","Service dates","Service locations","Individual case identification numbers","PMI numbers","Medical information","Diagnosis information","Treatment information","Healthcare provider names","Medications","Health insurance identification numbers","Health insurance claims information","MnCHOICES form information","\u003Cp>\u003Cstrong>The Aitkin County Health and Human Services 2026 data breach\u003C\u002Fstrong> was an incident involving unauthorized access to three Minnesota county employee email accounts between April 7 and April 8, 2026. The county’s official notice confirms that the attackers downloaded the contents of one account and that personal information and protected health information were affected.\u003C\u002Fp>\n\u003Cp>The public record maintained by the U.S. Department of Health and Human Services Office for Civil Rights lists 83,114 affected people and classifies the event as a Hacking\u002FIT Incident involving Email. LeakData imported no person or patient rows. importedRecordCount is zero, and this entry contains only incident metadata verified through its sources.\u003C\u002Fp>\n\u003Ch2>How Was the Aitkin County HHS Breach Confirmed?\u003C\u002Fh2>\n\u003Cp>The primary source is the four-page Notice of Cyber Incident published on Aitkin County’s official website on June 17, 2026. It directly explains the discovery date, access window for three accounts, download of data, MnCHOICES report, affected information categories, notification process, and measures taken by the county.\u003C\u002Fp>\n\u003Cp>The second source is the HHS OCR breach portal, which confirms the federal total of 83,114 people and the incident classifications. The third is HIPAA Journal’s July 10, 2026 report, which independently describes the access timeline, download, data types, and security improvements using the county notice and federal record.\u003C\u002Fp>\n\u003Ch2>What Happened Between April 7 and April 8, 2026?\u003C\u002Fh2>\n\u003Cp>On April 8, the county discovered that an email account belonging to a Health and Human Services employee was sending phishing messages. It secured the accounts and opened an investigation with nationally recognized cybersecurity and digital-forensics specialists. The review found unauthorized access to three county accounts from April 7 through April 8.\u003C\u002Fp>\n\u003Cp>The cybercriminals downloaded the contents of one County HHS employee account. The county reviewed the affected data to establish what information was present, who it related to, and where those people lived. The breachDate field uses April 7, 2026, the confirmed start of access, rather than the discovery or notification date.\u003C\u002Fp>\n\u003Ch2>Why Was the MnCHOICES Report Important?\u003C\u002Fh2>\n\u003Cp>The affected account contained a MnCHOICES report prepared by the Minnesota Department of Human Services. On May 13, the county confirmed that the report exposed viewable form-status information not only for people associated with Aitkin County but also for people with no county connection, and it promptly notified Minnesota DHS.\u003C\u002Fp>\n\u003Cp>The county and state agency then worked together to prepare written notices for the population in the report. This detail explains why the count of 83,114 exceeds Aitkin County’s population: the impact was not limited to county service recipients. The entry nevertheless creates no organization or subgroup totals that the sources do not disclose.\u003C\u002Fp>\n\u003Ch2>What Information Was Affected?\u003C\u002Fh2>\n\u003Cp>The county data varied by person and may include names, addresses, dates of birth, Social Security numbers, service dates and locations, individual case identifiers, PMI numbers, medical or health information, diagnosis and treatment information, healthcare-provider names, medications, and health-insurance identification numbers.\u003C\u002Fp>\n\u003Cp>Health-insurance claims, information about services received, MnCHOICES form types and statuses, and dates when forms were last modified were also involved. The DHS report had a narrower set: names, case identifiers, PMI numbers, form types and statuses, last-modified dates, and service-provider organizations or locations. The county did not say every field belonged to every person.\u003C\u002Fp>\n\u003Ch2>What Security Measures Did the County Take?\u003C\u002Fh2>\n\u003Cp>Aitkin County changed the passwords for affected accounts, retrained employees on email cybersecurity, and issued awareness communications about phishing messages. It also strengthened its email-retention policy to reduce the data scope of a future incident and said it continued evaluating additional tools, training, and third-party monitoring partnerships.\u003C\u002Fp>\n\u003Cp>The county notified Minnesota IT Services, HHS, and appropriate state regulators. It was unaware of misuse when the notice was issued, and the sources identify no ransomware group or leak site. Because the public documents do not offer complimentary credit monitoring, this entry does not add a promise of that service.\u003C\u002Fp>\n\u003Ch2>What Should Affected People Do?\u003C\u002Fh2>\n\u003Cp>Notice recipients should regularly review credit reports, account statements, health-insurance explanation-of-benefits notices, and medical-service histories for unfamiliar activity. If an unknown identity, medical-service, or insurance-claim entry appears, the relevant organization should be contacted through a verified channel; a fraud alert or free credit freeze may also be appropriate.\u003C\u002Fp>\n\u003Cp>The possible combination of Social Security numbers with health and insurance information creates lasting identity-theft and medical-fraud risk. Unexpected links claiming to come from Aitkin County, Minnesota DHS, MnCHOICES, or a healthcare organization should not be opened; contact should begin through an official number. LeakData does not host, distribute, or provide search access to downloaded email content.\u003C\u002Fp>","Official Aitkin County Notice of Cyber Incident confirming email-account access and download",false,"Medium","completed","\u002Fuploads\u002Flogo\u002Faitkin_county_mn.png"]