Skip to content
Back to Blog
critical severity June 15, 2026 · 5 min read

Nelson University Data Breach Notice (Washington Attorney General)

If you were named in this filing, here’s what the filing says was exposed, and what to do about it.

Nelson University notified Washington residents of a data breach in a filing reported to the Washington State Attorney General on June 15, 2026, and the notice lists name, social security number, driver's license or Washington ID card number, full date of birth, student ID number, health insurance policy or ID number, medical information and username and password/security question answers among the information exposed. The filing puts the incident itself on March 21, 2025.

Nelson University Data Breach Notice (Washington Attorney General)

The breach notice from Nelson University means that if you received a letter, your name, Social Security number, date of birth, driver’s license or Washington ID number, student ID, health insurance ID, medical information, and account credentials were exposed in an incident that occurred on March 21, 2025. The university did not file its notification with the Washington Attorney General until June 15, 2026 — 451 days later.

That long gap between the incident and the filing is the single most striking fact in the record. For more than fourteen months the university investigated, contained whatever happened, and only then told the 508 Washington residents whose records were involved. The filing itself contains no details on how the breach occurred or how long any data may have been accessible.

Your Social Security Number and Date of Birth Are Now Permanent Risks

A Social Security number combined with a full date of birth is the foundational pair used to open new credit accounts, file fraudulent tax returns, or create synthetic identities. Neither piece of information can be changed. Once it is out, it remains valuable to identity thieves for years.

The same record also lists driver’s license or Washington ID card numbers. These are frequently used alongside SSNs to bypass knowledge-based authentication at banks, government agencies, and credit bureaus. Medical information and health insurance policy numbers add another permanent vector: they can be used for insurance fraud, prescription scams, or to build a more convincing impersonation when applying for loans or jobs.

What the Password and Security Question Exposure Actually Means

The filing lists “username and password/security question answers” among the exposed categories. The record does not disclose whether these passwords were stored in plain text, weakly hashed, or protected with modern methods. Because the storage scheme is unknown, the safest assumption is that any password tied to your Nelson University account should be treated as compromised.

Change that password immediately on the university’s systems and, more importantly, anywhere else you reused it. Security questions are even weaker because the answers are often facts — mother’s maiden name, first pet, high school — that appear in other breached records. Treat every security question answer you ever gave Nelson University as public.

The Medical and Student Records Angle

Medical information and health insurance IDs were also exposed. This does not usually lead to immediate financial theft, but it can be used for fraudulent medical claims, prescription diversion, or to add credibility to impersonation attempts. Student ID numbers tied to your name and date of birth can help an attacker map your academic and employment history.

None of these categories can be canceled or reissued like a credit card. Their value does not expire when the news cycle moves on.

How to Determine Whether You Were Affected

Nelson University is required to notify affected individuals directly, usually by mail. If you have not received a letter, it is likely your records were not among the 508 affected. However, if you have moved since March 21, 2025, or changed addresses since you last interacted with the university, contact them directly to confirm whether your information was included. Absence of a letter is usually meaningful, but only the organization can give you a definitive answer.

The Long Notification Delay Changes the Practical Timeline

Because 451 days passed between the March 2025 incident and the June 2026 filing, any data taken in the breach has had more than a year to circulate. Identity thieves do not always strike immediately. They often wait for the story to fade before using the SSNs, dates of birth, and medical details to file taxes in January, open accounts, or submit insurance claims months or years later.

This extended window is why monitoring alone is not enough. You must assume the exposed identifiers will remain useful to criminals for the rest of your life unless you take active protective steps.

Credit and Identity Monitoring Is Necessary but Not Sufficient

Freezing your credit with the three major bureaus remains one of the most effective controls. It will not stop every form of fraud — tax refunds, certain medical claims, and some government benefits can still be targeted — but it blocks the majority of new-account identity theft that relies on your SSN and date of birth.

Place fraud alerts or full credit freezes at Equifax, Experian, and TransUnion. Review your Explanation of Benefits statements from every health insurer listed in your records. Look for claims you did not make. Request your tax transcript from the IRS every year to catch fraudulent filings early.

What Cannot Be Fixed

Your date of birth cannot be changed. Your Social Security number cannot be replaced on demand. The medical details and health insurance identifiers tied to your name are now facts an attacker can use indefinitely. The record offers no evidence that the passwords were strongly protected, so those must be considered lost.

These realities are why the 451-day delay matters. The longer data sits before notification, the more time criminals have to weaponize the permanent identifiers that cannot be revoked.

Practical Steps That Address This Specific Exposure

  • Change your Nelson University password immediately and treat every security question answer you used there as public. Then change the same password anywhere else you reused it.
  • Freeze your credit at Equifax, Experian, and TransUnion. This is the single most effective barrier against new-account fraud built on your exposed SSN and date of birth.
  • Review every Explanation of Benefits statement from your health insurers. Dispute any claims you do not recognize. Do this monthly for at least the next year.
  • Order your IRS tax transcript annually. Catch fraudulent filings before they trigger notices or liens.
  • Contact Nelson University directly if you have moved since March 2025 and have not received a letter. Only they can confirm whether your specific records were in the group of 508.

The filing is narrow. It tells us exactly which 508 people were affected, which categories were exposed, and when the university finally notified the state. It does not tell us how the breach happened or whether better technical controls would have prevented it. What it does tell you is that certain pieces of your identity are now permanently harder to protect. The practical response is to lock down what you still control and monitor the rest for the long term.

What to do now

Steps that match what this notice says was exposed

Every step below is free and you do it yourself, and none of it depends on Nelson University.

  1. Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
  2. Read your next explanation of benefits. Medical identity theft shows up as treatment you did not receive, billed to your policy and written into your medical record. Your insurer can flag the policy, and you can request an accounting of disclosures from the provider named here.
  3. Report the licence number to your state DMV. Most states will note the number as compromised, and some will issue a new one. It is the field that turns a stolen identity into a usable one in person.
  4. Expect the phone calls to get better. A date of birth is not secret, but it is what call centres use to confirm you are you. Treat any unexpected call that already knows your details as unverified until you call the company back yourself.

One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.

Report details & sourcing

Severity Critical identifiers that cannot be reissued, alongside documents or accounts that can be misused now
Disclosed June 15, 2026
Last reviewed July 22, 2026
Affected 508
Data exposed NameSocial Security NumberDriver's License or Washington ID Card NumberFull Date of BirthStudent ID NumberHealth Insurance Policy or ID NumberMedical InformationUsername and Password/Security Question Answers
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email