North Dakota’s Health and Human Services department says a phishing attack in late July exposed protected health information of about 1,700 people, most of them in the Bismarck region.
The state’s Information Technology Department identified the attack on July 21 and determined the next day that three employees in the Developmental Disabilities Division had interacted with the malicious email, giving attackers access to their accounts. NDIT secured the accounts, and the department’s review, completed August 14, found that roughly 1,690 of the affected individuals were in the Bismarck area, with 10 in the Dickinson and Grand Forks regions.
Exposed information may include names, contact details, dates of birth, age, Developmental Disabilities service information, and health plan names and identification numbers. The department has not said whether any of the data was used fraudulently.
The incident is a reminder that a single successful phishing click inside a state human services agency can expose sensitive health data for vulnerable populations, including people receiving disability services. Affected individuals should watch for suspicious calls, mail, and email, and report any suspected misuse of their information. Agencies reviewing the case may consider whether additional training, phishing-resistant authentication, or tighter email filtering could have stopped the compromise earlier.