Supply chain ⛓ Supply Chain

Minnesota Department of Human Services Vendor Breach — 304,000 Medicaid Recipients

📅 2026-01-20
Primary Source ↗

Incident Details

The Minnesota Department of Human Services notified approximately 304,000 people — primarily Medicaid and public benefits recipients — of a data breach involving a third-party vendor. The breach exposed sensitive government benefits data including names, Medicaid ID numbers, dates of birth, addresses, and in some cases Social Security numbers and medical information. Minnesota DHS administers Medicaid (Medical Assistance), SNAP (food assistance), and other public benefits programs. Government agency vendor breaches are particularly impactful as they expose data of vulnerable populations who cannot opt out of sharing information required to receive government benefits. The Minnesota Attorney General and HHS OCR were notified.

Technical Details

Initial Attack Vector
A third-party vendor providing services to the Minnesota Department of Human Services (DHS) suffered a data breach, exposing Medicaid and public benefits recipient data
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2026-01-20 Breach occurred
  2. 2026-01-20 Publicly disclosed