All Breaches
March 1, 2026 Verified Sensitive Record Government

Washington Department of Social and Health Services 2026 Data Breach

The Washington Department of Social and Health Services 2026 data breach was an insider-access incident discovered in March 2026 in which a DSHS employee accessed personal information in an internal client data system for reasons unrelated to the employee’s work. The agency confirms the person may have viewed names, dates of birth, Social security numbers, and Dshs client numbers.

The public record maintained by the U.S. Department of Health and Human Services Office for Civil Rights lists approximately 8,600 affected people and classifies the event as Unauthorized Access/Disclosure involving a Laptop. LeakData imported no client rows. importedRecordCount is zero, and this entry contains verified incident metadata only.

How Was the Washington DSHS Breach Confirmed?

The primary source is the three-page Notice of Data Breach published on DSHS’s official website. The agency letter explains the month of discovery, former employee’s access, fields that may have been viewed, excluded health details, termination of system access, cooperation with law enforcement, and recommended steps for affected people.

The second source is the HHS OCR breach portal, which confirms the scope of 8,600 people and the federal incident classifications. The third is HIPAA Journal’s June 30, 2026 report, which independently describes the insider access, data categories, departure of the employee, and DSHS response using the official notice.

What Was Discovered in March 2026?

DSHS discovered in March that an employee had accessed personal information in its internal client data system for reasons unrelated to the person’s duties. The agency immediately ended the employee’s access to DSHS systems, reviewed the history of the person’s activity and client-data access, and cooperated with state and local law enforcement in an ongoing investigation.

The public notice does not identify the first or last day of unauthorized viewing or say how long it continued. This entry therefore creates no exact access window; the breachDate field uses March 1, 2026 only to represent the disclosed month-level timing. It must not be read as the exact day of access or discovery.

What Information May Have Been Viewed?

According to the DSHS review, the former employee may have viewed a client’s name, date of birth, Social Security number, DSHS client number, and the general category of services received. These fields are sensitive personal information that could support identity theft, attempted account takeover, or targeted social engineering.

The agency specifically said it found no evidence the employee accessed particular health information such as diagnoses, test results, treatments, health-insurance claims, or chart notes. The entry therefore reports a general service category but adds no undisclosed diagnosis or detailed medical record. Download, external transfer, or public release of files has not been confirmed.

What Does the Scope of 8,600 People Mean?

The pwnCount and totalRecords fields use the 8,600 affected-person value in HHS OCR’s public row dated June 30, 2026. DSHS said it took a cautious approach by contacting every client whose information the employee may have viewed, even if particular access might have been related to work.

The total is not a count of confirmed misuse; it is the notification population. The sources do not say every field belonged to every person or establish that information for all 8,600 people was actually viewed. This entry therefore creates no field-level subgroup counts and does not add document, row, or access-event counts to the number of people.

What Measures Did DSHS Take?

The agency terminated the employee’s DSHS system access immediately after identifying the activity and reviewed the person’s historical actions. DSHS also said it was implementing additional safeguards, reviewing data-privacy and security policies and procedures, and assisting the continuing investigation by state and local law enforcement.

HIPAA Journal confirms the person no longer works for DSHS, but the sources do not say whether the person was fired because of the incident or departed another way. Because the official documents offer no complimentary credit monitoring, this entry adds no such service. The event is not linked to an external attacker, malware, ransomware group, or leak site.

What Should Affected DSHS Clients Do?

Notice recipients should regularly review DSHS account activity, bank and payment-card statements, and credit reports for unfamiliar events. If suspicious activity appears, DSHS should be contacted through an official channel; reports to the Federal Trade Commission, Washington Attorney General, and local law enforcement may also be appropriate.

The combination of a Social Security number and date of birth requires long-term attention. Client numbers, passwords, or identity details should not be shared through unexpected calls, texts, or links claiming to represent DSHS; contact should begin through the verified number in the notice. LeakData does not host, distribute, or provide search access to DSHS client data.

8.6 Thousand
Affected Accounts
6
Data Types
Low
Severity
Yes
Verification

Exposed Data Types

6
Personal information
Names
Dates of birth
Social security numbers
Dshs client numbers
General categories of services received

Additional Information

Added DateJuly 27, 2026
Breach DateMarch 1, 2026
Domaindshs.wa.gov
SourceOfficial Washington DSHS notice confirming unauthorized employee access to client data
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information