Department of Health and Human Services
ent_758279849969e222be74d608
Disclosures
4
State AG · 3 jurisdictions
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
9,300
as filed · State AG NH
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Department of Health and Human Services
- Normalized
- department of health and human— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- Illinois State AGas victim2025-06-01
DEPARTMENT OF HUMAN SERVICES filed a data-breach notice with the Illinois Attorney General in June 2025 (case 25-06-217). The register records the breach as discovered on February 25, 2025. Personal information types reported: medical information, ssn. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2025-06-01
DEPARTMENT OF HUMAN SERVICES filed a data-breach notice with the Illinois Attorney General in June 2025 (case 25-06-256). The register records the breach as discovered on March 11, 2025. Personal information types reported: medical information. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Montana State AGas victim2016-04-14
Montana DPHHS Early Childhood Services Bureau notified individuals that a former employee unauthorizedly disclosed personal information, including Taxpayer ID/SSN, in a spreadsheet sent to state legislators. The breach was an insider misuse of valid accounts. Remediation included employee education and offering one year of credit monitoring via Experian.
- New Hampshire State AGas victim2008-12-16
The New Hampshire Department of Health and Human Services (DHHS) inadvertently sent an email attachment containing personally identifiable information (name, address, Social Security number) and Medicare Part D plan details for approximately 9,300 individuals to a list of health care providers on December 1, 2008. DHHS immediately contacted recipients to delete the information and confirmed deletion by most. No evidence of misuse was found. Affected individuals were notified via mail on December 15, 2008, and advised to place fraud alerts.