Missouri Department of Conservation breach exposed employee health plan data

Organization
Missouri Department of Conservation
Exploit
Hacking
Industry
Government

The Missouri Department of Conservation disclosed on 30 May 2025 that a breach of one of its servers had exposed personal and health information belonging to current and former beneficiaries of its employee health benefits plan.

The agency's cybersecurity team identified unauthorised access to the server in February 2025 and activated its incident response team. An initial review of the available information suggested that no protected health information covered by the HIPAA Privacy Rule had been affected. Further analysis in April changed that assessment, when the department determined that some of the files caught up in the intrusion did contain health plan records.

The department said the exposed information could include names, addresses, telephone numbers, email addresses, dates of birth and health benefits enrolment details, and in some cases Social Security numbers, driver's licence numbers or state identification numbers. It did not publish a count of affected individuals.

The department said it was working with law enforcement and third party cybersecurity experts on the continuing investigation and had implemented additional security measures. It offered complimentary credit monitoring, sent written notices to those it could reach and posted a substitute notice online for people whose contact details were incomplete. Affected individuals were advised to watch their accounts and benefits statements for unfamiliar activity, and were given a departmental telephone line and a privacy support email address for questions.

Sources