Skip to content
Back to Blog
critical severity June 30, 2026 · 4 min read

Washington Department of Social Health Services Data Breach Notice (Washington Attorney General)

If you were named in this filing, here’s what the filing says was exposed, and what to do about it.

Washington Department of Social Health Services notified Washington residents of a data breach in a filing reported to the Washington State Attorney General on June 30, 2026, and the notice lists name, social security number, full date of birth and protected health information owned or licensed by a HIPAA covered entity among the information exposed. The filing puts the incident itself on September 23, 2023.

Washington Department of Social Health Services Data Breach Notice (Washington Attorney General)

The Washington Department of Social and Health Services has confirmed that a data breach on September 23, 2023 exposed the names, Social Security numbers, full dates of birth, and protected health information of 8,600 people. The state filing reporting the incident was submitted on June 30, 2026 — 1,011 days, or roughly 33 months, later.

A long delay between the breach and public notice

The gap between the September 23, 2023 incident date and the June 30, 2026 filing is the most striking detail in the record. Notification timelines vary by state law and the time required to complete an investigation, so the filing itself does not label the interval as unusual. What matters to anyone whose records were included is that nearly three years passed before the official notice reached the Attorney General’s office.

What the exposed information actually enables

A Social Security number paired with a full date of birth remains one of the highest-value combinations for identity theft. Criminals use this pair to open new credit accounts, file fraudulent tax returns, or create synthetic identities that can persist for years. Because neither piece of information can be reissued like a credit card or password, the risk does not expire when the news cycle moves on.

The inclusion of protected health information owned or licensed by a HIPAA covered entity adds another permanent concern. Medical records can be used for insurance fraud, prescription scams, or blackmail. Unlike financial accounts that can be frozen, health data cannot be “canceled.” Once it is out, it stays out.

No passwords were exposed in this incident. That is genuinely good news. You do not need to change any DSHS-related password because of this breach, and there is no evidence that account credentials themselves were compromised.

How to tell whether your records were affected

The Department of Social and Health Services is required to notify affected individuals directly, usually by mail to the last known address. If you have not received a letter, it is likely that your information was not included in the group of 8,600 people. However, if you have moved since September 23, 2023, letters may have gone astray. In that case, contact the Department directly to confirm whether you were part of this filing.

The lifelong nature of these records

Name, Social Security number, and date of birth do not lose their value over time the way a stolen credit card number does. The same combination that opens an account today can be used again in five or ten years when memories of the breach have faded. This is why the exposure of these particular categories matters far more than the number of people affected.

Protected health information carries similar permanence. Once medical details are linked to your identity, they can surface in unexpected places — unauthorized insurance claims, employment background checks, or even targeted fraud schemes that rely on knowing your medical history.

What remains under your control

While you cannot change your Social Security number or date of birth, you can still limit what criminals do with them. Placing a freeze on your credit reports prevents new accounts from being opened in your name without your explicit permission. Monitoring your Explanation of Benefits statements from every health insurer helps catch fraudulent claims before they affect your coverage or premiums.

Because this breach involves both identity documents and health data, the two areas require separate but coordinated attention. Credit monitoring addresses the SSN risk. Regular review of insurance statements addresses the medical-record risk. Neither step undoes the breach, but both reduce what an attacker can accomplish with the stolen information.

The scale in context

The filing states that 8,600 Washington residents were affected. That number is now printed beside this article. The record does not describe how the information was accessed, whether it was copied, or what security measures were in place at the time. Those details remain outside what the Attorney General’s notification discloses.

The categories listed — name, Social Security number, full date of birth, and protected health information — are the only ones confirmed in the filing. No other data types, including financial account numbers or passwords, appear in the record.

Practical steps that address this specific exposure

  • Freeze your credit reports at Equifax, Experian, and TransUnion. This stops new accounts from being opened with your Social Security number and is the single most effective control available after this type of breach.
  • Review every Explanation of Benefits statement from your health insurers. Look for claims you did not file or services you did not receive. Report discrepancies immediately.
  • Set up free fraud alerts with the three major credit bureaus. A fraud alert requires lenders to verify your identity before issuing new credit and lasts for one year (or seven years with an extended alert).
  • Obtain your annual free credit reports and scan for unfamiliar accounts. Check them now and again in six months, as fraudulent activity may appear slowly.
  • Contact the Washington Department of Social and Health Services if you moved after September 2023. Confirm whether your records were part of the 8,600 affected individuals.

The breach notice itself cannot tell you whether the data was exfiltrated or simply viewed. It cannot confirm encryption status at the time of the incident. What it does confirm is that these four categories left the Department’s control on September 23, 2023 and that official notice arrived 1,011 days later. The steps above are the practical measures that still work after that fact.

What to do now

Steps that match what this notice says was exposed

Every step below is free and you do it yourself, and none of it depends on Washington Department of Social Health Services.

  1. Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
  2. Read your next explanation of benefits. Medical identity theft shows up as treatment you did not receive, billed to your policy and written into your medical record. Your insurer can flag the policy, and you can request an accounting of disclosures from the provider named here.
  3. Expect the phone calls to get better. A date of birth is not secret, but it is what call centres use to confirm you are you. Treat any unexpected call that already knows your details as unverified until you call the company back yourself.

One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.

Report details & sourcing

Severity Critical identifiers that cannot be reissued, alongside documents or accounts that can be misused now
Disclosed June 30, 2026
Last reviewed July 22, 2026
Affected 8600
Data exposed NameSocial Security NumberFull Date of BirthProtected Health Information owned or licensed by a HIPAA covered entity
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email