Blog > Data Breach & Privacy

Washington DSHS Data Breach: What Affected Clients Need to Know

The Washington Department of Social and Health Services (DSHS) has disclosed an insider data breach affecting approximately 8,600 individuals. If you received a Notice of Data Breach from DSHS, here is what happened and what steps you can take.

Washington DSHS Data Breach: What Affected Clients Need to Know

What Happened in the Washington DSHS Data Breach

An insider access incident affecting thousands of clients

According to the department’s Notice of Data Event, on or about March 2026 DSHS became aware of suspicious activity involving its internal systems. The investigation determined that a DSHS employee accessed confidential client information for reasons unrelated to their job responsibilities. DSHS reported that it took action to investigate, secured its systems, terminated the employee’s access, and strengthened its overall security posture.

DSHS began sending written notification letters to affected individuals in June 2026, and the incident was reported to the U.S. Department of Health and Human Services’ Office for Civil Rights. Insider breaches — where a person with legitimate access misuses it — are a recognized risk in government and healthcare settings, and they can be difficult to detect without active monitoring of access logs.

What Information Was Involved in the DSHS Breach

The categories of personal data accessed

According to public reporting, the information the employee potentially accessed included full names, dates of birth, Social Security numbers, DSHS client numbers, and program enrollment details. DSHS stated that there was no evidence the employee had access to specific health information such as diagnoses, test results, treatments, claims, or chart notes.

Even without clinical details, the combination of names, dates of birth, and Social Security numbers is highly sensitive. Those elements are enough for identity thieves to attempt to open accounts or commit fraud, which is why DSHS advised affected individuals to monitor their accounts and credit reports for suspicious activity.

Who Is Affected and What the Risks Are

Understanding your exposure as a DSHS client

DSHS reported that approximately 8,600 individuals may have been affected. Because DSHS serves individuals and families relying on social and health services, many affected people are clients whose information the department maintained as part of program administration.

When personal information is accessed by someone acting outside the scope of their duties, the concern is not only what was viewed but how that information could be used or shared. Remaining vigilant over time is important, as exposed identity information can be misused long after the initial incident.

What to Do If You Received a DSHS Notice

Protective steps for affected individuals

Keep your notification letter, as the specific data elements involved vary by individual and are detailed in each letter. Monitor your financial accounts and review your free credit reports at AnnualCreditReport.com for unfamiliar accounts or activity. You may also consider placing a fraud alert or a credit freeze with the major credit bureaus for added protection.

Because DSHS did not indicate in its notice that it was offering credit monitoring, affected individuals may want to take these protective steps proactively. A legal professional can also help you understand whether you may have legal options following the incident.

See our overview of the MBE CPAs data breach lawsuit for details on another reported incident.

FAQs

DSHS became aware of the suspicious activity on or about March 2026 and began sending notification letters in June 2026.

DSHS reported that approximately 8,600 individuals may have been affected.

Public reporting indicated the involved information included full names, dates of birth, Social Security numbers, DSHS client numbers, and program enrollment details.

DSHS stated there was no evidence the employee had access to specific health information such as diagnoses, test results, treatments, claims, or chart notes.

DSHS did not indicate in its notice that credit monitoring was being offered, but it provided guidance on monitoring accounts and credit reports. Affected individuals may want to take protective steps proactively.

You may have legal options if your information was involved. A legal professional can review your situation during a free consultation.

Related Content

Guides, nearby offices, and related practice areas.

Start Your Free Case Review

4.9 out of 2,521 reviews
  • Available 24/7
  • Hablamos Español
  • Nationally-Recognized Powerhouse Team
As seen in:

We'll contact you within minutes

No fees unless you get paid.

By submitting this form, you knowingly, voluntarily, and expressly consent to receive from Wilshire Law Firm telephone calls, emails, and SMS text messages, including those made using an automatic telephone dialing system (auto-dialer), artificial intelligence (AI), and/or pre-recorded or artificial voice messages. These communications are for the purpose of providing prompt consultation regarding your potential case. You understand that by providing your telephone number, you are granting permission to be contacted for this purpose, even if your number is on a federal or state Do-Not-Call registry. Consent is not required as a condition of retaining Wilshire Law Firm. Message and data rates may apply. You may revoke your consent to receive calls, texts, or emails at any time by replying “STOP” to any text message, calling 888-557-3271, filling out the form at wilshirelawfirm.com/do-not-contact or by any other reasonable method. For more information, refer to our Privacy Policy.

Locations

Find your nearest office — serving all of California and employment clients in Oregon and Washington.

Appointments required for office visits

Beverly HillsIrvineLos AngelesOaklandRiversideSacramentoSan DiegoTorrance