[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fw76m65x50xsh":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":12,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":17,"affectedCountUnit":19,"hasEnglishDescription":4,"severity":20,"dataClasses":21,"description":25,"seoTitle":26,"seoTitleEn":8,"seoDescription":26,"seoDescriptionEn":27,"logoUrl":28,"isVerified":4,"isSensitive":29,"isSpamList":29,"isMalware":29,"company":30},"6a7094d438a556e6d9a74127","MaximusNebraskaPDMS2026","Maximus Nebraska PDMS 2026 Data Breach","maximus-nebraska-pdms-2026","maximus.com","2026-04-27T00:00:00.000Z","2026-08-03T13:17:08.664Z","2026-08-03T13:19:22.375Z","Maximus consumer notice filed with Massachusetts and independent event report","https:\u002F\u002Fwww.mass.gov\u002Fdoc\u002F2026-1236-maximus-us-services-inc\u002Fdownload",[15],null,"unknown","people","Unknown",[22,23,24],"Names","Dates of birth","Social Security numbers","\u003Cp>\u003Cstrong>The 2026 Maximus Nebraska PDMS data breach\u003C\u002Fstrong> affected the Provider Data Management System operated by Maximus US Services for the Nebraska Department of Health and Human Services. Maximus learned of the incident on April 27, 2026 and determined that first and last names, dates of birth, and Social Security numbers may have been affected.\u003C\u002Fp>\u003Cp>PDMS is the provider-management system used to enroll healthcare professionals who serve Nebraska Medicaid members. The public notice identifies this as a distinct event from older, unrelated security incidents involving Maximus.\u003C\u002Fp>\u003Ch2>How did the Maximus data breach happen?\u003C\u002Fh2>\u003Cp>According to Maximus's official consumer notice, the company learned of a security incident involving the Nebraska Provider Data Management System on April 27, 2026. It contacted Nebraska DHHS that day and supplied the agency with additional information on April 28.\u003C\u002Fp>\u003Cp>Maximus investigated with an external forensic firm and determined on June 16, 2026 that some personal information may have been affected. The public notice does not disclose the initial-access date, duration, method, or whether a file was conclusively acquired. April 27 is therefore the date Maximus learned of the event, not a confirmed intrusion-start date.\u003C\u002Fp>\u003Ch2>What information may have been affected?\u003C\u002Fh2>\u003Cp>The official notice limits the potentially affected fields to first and last names, dates of birth, and Social Security numbers. It does not publicly identify addresses, bank accounts, payment cards, medical records, or health insurance information as affected, so those fields are not included in this event.\u003C\u002Fp>\u003Cp>PDMS is a healthcare-provider enrollment system. The incident should not be interpreted as exposure of the general Nebraska Medicaid patient database; the public evidence supports only the identity information described in notices sent to affected people.\u003C\u002Fp>\u003Ch2>How many people were affected?\u003C\u002Fh2>\u003Cp>Neither Maximus nor the public Massachusetts regulatory filing discloses a nationwide affected-person total. The total number of affected people remains unknown unless a new verifiable official figure is published.\u003C\u002Fp>\u003Cp>The combination of a Social Security number and date of birth can increase the risk of identity theft, fraudulent credit applications, and tax fraud. An attacker familiar with Nebraska Medicaid provider enrollment could also use that context to create more convincing phishing messages.\u003C\u002Fp>\u003Ch2>How did Maximus respond?\u003C\u002Fh2>\u003Cp>Maximus said it worked with Nebraska DHHS to strengthen processes, obtained forensic support, and notified appropriate law enforcement. Affected people were offered 24 months of complimentary Experian IdentityWorks credit monitoring and identity-protection services, with an enrollment deadline of October 31, 2026.\u003C\u002Fp>\u003Ch2>What should affected people do?\u003C\u002Fh2>\u003Cp>Recipients can activate the complimentary protection service using the code in the verified letter, review credit reports, and consider a credit freeze or fraud alert. Social Security account activity and tax correspondence should be monitored for unfamiliar activity.\u003C\u002Fp>\u003Cp>Unexpected emails or calls invoking PDMS, Maximus, Nebraska Medicaid, or Experian should be verified independently through the contact channels in the mailed notice. Any unfamiliar credit, tax, or identity transaction should be reported directly to the relevant organization and documented.\u003C\u002Fp>","","The Maximus Nebraska PDMS data breach may have exposed names, dates of birth, and Social Security numbers. Review the scope and protective steps.","\u002Fuploads\u002Flogo\u002Fmaximus-official.svg",false,{"name":31,"sector":32,"country":33,"website":34,"websiteArchiveUrl":26,"websiteStatus":26,"websiteCheckedAt":17},"Maximus US Services, Inc.","Government Services","United States","https:\u002F\u002Fmaximus.com\u002F"]