Why It Matters
A cyberattack on North Dakota’s health and human services agency has put sensitive records at risk for about 1,700 state residents who depend on developmental disability programs — a vulnerable population whose exposed files may contain medical histories, health plan details, and guardian data.
What Happened
The North Dakota Department of Health and Human Services disclosed Monday that a phishing campaign in July successfully deceived three workers within its Developmental Disabilities Division into engaging with a malicious email. The interaction opened those employees’ accounts to unauthorized outside access.
State IT personnel uncovered the intrusion and locked down the affected accounts after conducting an investigation. The vast majority of the roughly 1,700 people whose data may have been compromised live in and around Bismarck.
The scope of potentially exposed data is significant: records could include full names, contact details, birth dates, developmental disability service histories, health plan names and ID numbers, medical records, and information about individuals’ legal guardians.
Official Response
Written notices have been sent to everyone believed to be affected. The agency has also filed reports with two oversight bodies — the U.S. Department of Health and Human Services Office for Civil Rights and the North Dakota Attorney General’s Office — as required under federal health privacy regulations.
“HHS takes the privacy and security of protected health information seriously,” the department told the North Dakota Monitor publicly. “We are working closely with NDIT to strengthen safeguards, enhance cybersecurity awareness training, and prevent similar incidents.”
People who believe they may be affected can reach department contact Kristen Vander Vorst at (800) 755-8529.
By the Numbers
3 — division employees who engaged with the phishing message
~1,700 — total individuals whose records may have been accessed
July 2026 — the month the attack took place
2 — regulatory authorities formally notified of the incident
Zoom Out
State agencies administering health and social services have become frequent targets for phishing campaigns, in large part because of the volume of sensitive personal and medical data they maintain. Departments serving individuals with disabilities are particularly attractive to bad actors given the breadth of records they hold, which often include both financial and clinical information.
Across the country, state governments have been investing in upgraded cybersecurity infrastructure and employee training programs in response to a rising number of successful intrusions at government agencies. North Dakota’s incident adds to a pattern that federal authorities have flagged as a growing threat to public sector data systems.
What’s Next
The department has pledged to work alongside state technology officials to reinforce its defenses and expand staff awareness training. No specific deadline for completing those upgrades was announced. Affected individuals are encouraged to monitor their health plan accounts for unusual activity and to reach out to the department’s designated representative with any concerns.