Skip to main content
Back
Nebraska Department of Administrative Services

Nebraska Department of Administrative Services Data Breach (2015)

Nebraska Department of Administrative Services

lowVERIS
Disclosed

January 1, 2015

4103 days ago

Records

Undisclosed

Confirmed

Root Cause

Misconfiguration

Industry

Government

Description

On August 29, 2018, Department of Administrative Services was notified by Health Fitness Corporation ("HealthFitness"), a former vendor for the State of Nebraska, that certain records relating to health coaching were being stored on a server that was inadvertently searchable on the Internet due to a software misconfiguration. HealthFitness found evidence that web crawlers accessed these files, at least as early as August of 2015. Most of these files were scanned documents and many contained handwritten information, which is not easily recognizable by web crawlers and search engines. Upon discovery, HealthFitness immediately removed the files and began an investigation using both internal resources and third-party forensic investigators to identify potentially impacted individuals. On September 21, 2018, HealthFitness mailed notice letters to individuals whose information was contained in the files. HealthFitness has offered potentially impacted individuals access to credit monitoring and identity theft protection services for one year without charge.