Data breach exposes personal and medical details of thousands of Labor Department staff
A leak of a spreadsheet containing personally identifiable and health information affected nearly 3,150 Labor Department employees who had filed accommodation requests.
An internal memo revealed that a Labor Department employee with authorized access incorrectly emailed a spreadsheet containing personally identifiable and protected health information to a personal address outside the agency, and the mistake was repeated. The data breach impacted nearly 3,150 staff members who had requested reasonable accommodations from October 2023 through June 1, 2026, exposing names, duty locations, job titles, supervisors, pay grades, and details of their disabilities or medical conditions.
The department sent mailed notifications to each affected employee and is evaluating further measures to protect the data. Union officials expressed frustration over the month-long gap before employees were informed and the absence of information about the sender’s role or why the emails were sent repeatedly. The department also noted a backlog of accommodation requests and is considering AI tools to manage the workload, though experts warned of privacy risks. The Labor Department did not respond to a request for comment.
Why it matters
Sensitive personal and medical data of federal workers were exposed, raising privacy and security concerns.
In this story
