Texas HHSC says employees improperly accessed data of about 94,000 people
- Organization
- Texas Health and Human Services Commission
- Exploit
- Malicious Insider
- Industry
- Government
The Texas Health and Human Services Commission said on April 30, 2025 that it was notifying 33,529 more people that their personal and protected health information had been improperly accessed by agency staff. The announcement followed a January 2025 disclosure covering 61,104 individuals, bringing the running total to roughly 94,000 recipients of state benefits.
The agency said improper access by its own employees stretched from June 2021 to January 2025. Nine HHSC employees were fired for viewing beneficiary accounts without a stated business reason. Two of the seven dismissed in the first round were accused of stealing from recipients' food benefit cards.
The records involved included full names, home addresses, telephone numbers, dates of birth, email addresses, Social Security numbers, Medicaid and Medicare identification numbers, and financial, banking, employment, benefits, health and insurance information.
The commission also disclosed that an employee of Maximus, a contractor handling enrollment services for the state, had improperly accessed protected health information between May 8, 2023 and February 28, 2025. That conduct surfaced during the agency's investigation of its own staff. Maximus terminated the employee, characterized the matter as an isolated incident involving a single worker, and offered those affected two years of credit monitoring and identity theft protection.
HHSC referred the cases to its Office of Inspector General for investigation and coordination with prosecutors, offered affected individuals two years of free credit monitoring and identity theft protection, and said it was continuing to review whether recipients of other programs were affected.