Kootenai County, Idaho Data Breach Notice (Washington Attorney General)
If you were named in this filing, here’s what the filing says was exposed, and what to do about it.
Kootenai County, Idaho notified Washington residents of a data breach in a filing reported to the Washington State Attorney General on July 22, 2026, and the notice lists name, social security number, driver's license or washington id card number, full date of birth, health insurance policy or id number, medical information and biometric data among the information exposed.
The exposure of your biometric data changes the risk picture permanently. Unlike a password or credit card, a fingerprint or facial scan cannot be reissued. Combined with your name, Social Security number, date of birth, driver’s license number, health insurance ID, and medical information, this single incident gives identity thieves a lifelong set of tools that are difficult to revoke.
Kootenai County, Idaho filed notice with the Washington Attorney General on July 22, 2026, stating that information belonging to 746 people was exposed. The filing lists exactly those seven categories and no others. No passwords or login credentials appear in the exposed data.
Why Biometric Data Makes This Breach Different
Biometric identifiers are intended to be unique and permanent. Once they leave an organization’s control, there is no practical way for you to change them. The same record that holds your fingerprint or iris scan also holds the personal details attackers need to link that biometric to your identity across government, healthcare, and financial systems.
This combination is particularly dangerous in healthcare-related identity fraud. With your medical information, health insurance policy number, and full date of birth, someone can impersonate you to obtain care, file fraudulent claims, or create synthetic identities that mix your real medical history with fabricated details. Those records can follow you for decades.
What the Exposed Fields Enable
A Social Security number paired with a date of birth remains one of the most valuable combinations for opening new accounts in another person’s name. The addition of your driver’s license or Washington ID number makes it easier to obtain official documents or pass identity verification at government agencies.
Medical information and health insurance identifiers open a separate avenue of fraud. Thieves can use them to bill insurance companies for treatments that never occurred, potentially leaving you to resolve incorrect medical records or unexpected bills years later. Because the filing confirms medical information was exposed, this risk cannot be dismissed.
The absence of passwords in the exposed categories is genuine good news. You do not need to change any password connected to Kootenai County services as a direct result of this incident. That particular worry does not apply here.
How to Determine Whether This Filing Affects You
Kootenai County is required to notify affected individuals directly, usually by mail. If you received a letter from the county, your information was included in this exposure. If you have not received a letter, it is likely you were not part of the group of 746 people affected. However, anyone who has moved since the incident should contact Kootenai County directly to confirm their status, because notification letters can miss people who have changed addresses.
The filing does not state when the incident itself occurred, only that the notification was filed on July 22, 2026. This means the letter itself is the most reliable indicator available to you.
The Lifelong Nature of These Identifiers
Most of the data listed in this filing cannot be replaced. Your biometric data is permanent. Your Social Security number, once compromised, stays compromised. Your date of birth never changes. Even your driver’s license number, while technically replaceable, creates a trail that links back to the original breach for years.
This is why the exposure of medical information alongside these permanent identifiers matters. Healthcare records tied to your real identity are difficult to disentangle once they are mixed with fraudulent activity. The 746 people named in this filing now carry that added risk for the rest of their lives unless they take deliberate protective steps.
Concrete Protections That Address This Specific Exposure
Place a freeze on your credit reports at Equifax, Experian, and TransUnion. This prevents new accounts from being opened in your name using the Social Security number and date of birth now known to be exposed. The freeze is free and can be lifted temporarily when you need to apply for credit.
Review every Explanation of Benefits statement from your health insurance provider. Look for claims you do not recognize. Because medical information and your health insurance ID were exposed, fraudulent billing is a realistic possibility. Catching it early limits damage to your medical record and your finances.
Request your annual free credit reports and examine them for accounts you did not open. Pay particular attention to any activity that began after July 2026. The combination of identifiers in this breach makes synthetic identity fraud more likely over a multi-year period.
Consider placing an extended fraud alert on your credit file, which lasts for seven years. This requires creditors to take extra steps to verify your identity before issuing new credit. Given the permanent nature of the biometric and Social Security number exposure, the longer protection period aligns with the duration of the risk.
Contact Kootenai County directly if you have not received a notification letter but believe you may have interacted with their services in Washington. Ask specifically whether your records were part of the group of 746 affected individuals. Do not rely on general assurances; request confirmation tied to your name and date of birth.
What Cannot Be Fixed and What Still Can
The biometric data is gone for good. There is no reset button for fingerprints or facial geometry once they have been exposed. The same is true for the linkage between your name, Social Security number, and medical history. Accepting that reality early allows you to focus limited time and energy on the protections that remain available.
What you can still control is how aggressively you monitor the downstream consequences. Consistent review of credit reports, insurance statements, and official mail reduces the window during which thieves can profit from this data before being detected. The filing’s limited scope—exactly seven categories for exactly 746 people—means the exposure is contained compared with many larger breaches, but the permanence of several of those categories makes individual vigilance essential.
The record provides no information about how the data was accessed or whether it was copied and exfiltrated. It simply establishes that these categories left Kootenai County’s control and that Washington residents were notified. That is the only foundation this analysis can stand on.
Because biometric data cannot be changed, the prudent assumption is that the full set of identifiers may be used in future attempts at impersonation. The steps above do not eliminate that possibility, but they shrink the practical opportunities available to someone using your stolen information. In a breach that includes permanent identifiers, shrinking the attack surface is the realistic goal.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on Kootenai County, Idaho.
- Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
- Read your next explanation of benefits. Medical identity theft shows up as treatment you did not receive, billed to your policy and written into your medical record. Your insurer can flag the policy, and you can request an accounting of disclosures from the provider named here.
- Report the licence number to your state DMV. Most states will note the number as compromised, and some will issue a new one. It is the field that turns a stolen identity into a usable one in person.
- Expect the phone calls to get better. A date of birth is not secret, but it is what call centres use to confirm you are you. Treat any unexpected call that already knows your details as unverified until you call the company back yourself.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
Report details & sourcing
Related breaches
Trezor Shipping Data Breach — 13,689 Hardware Wallet Buyers, Home Addresses Included
ShipMonk, a logistics provider used by Trezor, was breached through a vulnerability in the third-par…
Match Group (Tinder, Hinge, OkCupid) Data Breach — January 2026
ShinyHunters claimed responsibility for stealing over 10 million Match Group user records in early 2…
Crunchbase Massive Personal Records Leak — January 2026
ShinyHunters exfiltrated approximately 2 million records from the business-intelligence platform Cru…