Maximus Data Breach Exposes Social Security Numbers and Personal Data

Healthcare data breach illustration
Breach Discovery: April 2026Breach Notification: July 2026

What Happened in the Maximus Data Breach?

Maximus US Services, Inc. recently confirmed a data security incident tied to a system it manages for the state of Nebraska. The company runs the Provider Data Management System, or PDMS, on behalf of the Nebraska Department of Health and Human Services. This platform holds enrollment records for healthcare providers who participate in the state’s Medicaid program.

According to the company, unauthorized access to the system occurred in April 2026. Maximus discovered the intrusion and, that same day, alerted Nebraska DHHS. The company followed up with additional details to the state agency the next day. However, Maximus has not identified a specific attack method, such as phishing or ransomware, that led to the breach.

After discovery, Maximus brought in an outside digital forensics firm to review the affected systems. That review wrapped up roughly seven weeks later, in mid-June 2026, when investigators confirmed that personal information tied to certain individuals had likely been accessed without permission. As a result, Maximus began mailing notification letters to affected people in July 2026.

Throughout this process, Maximus says it cooperated closely with Nebraska DHHS and also notified law enforcement. This kind of multi-week gap between discovery and notification is fairly typical. Forensic teams often need time to determine precisely whose data was touched and which categories of information were involved before a company can notify anyone accurately.

Who was affected?

The people affected by this breach appear to be healthcare providers who were enrolled in Nebraska’s Medicaid provider system at the time of the incident. This is a somewhat different population than a typical consumer breach, since it centers on medical providers rather than patients. Even so, the exposed information could still be used to commit serious identity fraud against these individuals.

Maximus has not publicly disclosed exactly how many people were affected. The company also has not said whether providers outside Nebraska, or any patients whose records might connect to those provider profiles, were involved. Because this system underpins a statewide Medicaid program, the population size could range from a relatively small group to several thousand enrolled providers.

It is also worth noting that government contractors like Maximus often manage similar systems across multiple states. While this notification specifically addresses Nebraska, affected individuals should not assume the scope is limited unless the company clarifies that further in future updates.

What Information Was Potentially Exposed?

Based on the notification letter Maximus sent to affected individuals, the exposed data centers on a few key identifying details. This combination is often enough by itself to enable identity theft, even without any financial account numbers being involved.

  • Full first and last names
  • Dates of birth
  • Social Security numbers

Maximus has not said whether other categories of information, such as bank account details, medical records, or provider license numbers, were also exposed. The notification letter focuses specifically on these three data types.

When a Social Security number is paired with a full name and date of birth, criminals can use that combination to open new credit accounts, apply for loans, or file fraudulent tax returns in someone else’s name. This type of fraud can be difficult to detect right away because it often does not involve an existing account the victim already monitors.

In addition, because this breach hit a provider enrollment system rather than a typical consumer database, affected individuals may also face risks tied to professional identity theft. For example, a bad actor could attempt to misuse a provider’s identifying information to submit fraudulent billing claims under someone else’s name. This makes vigilance especially important for the healthcare professionals impacted here.

What is the company doing?

Once Maximus discovered the incident, the company moved to contain it and launched an internal investigation immediately. It also engaged an independent forensic firm to determine the full scope of what happened before notifying anyone. This step helped ensure the notifications sent to affected individuals were as accurate as possible.

In response to the confirmed exposure, Maximus is now offering affected individuals 24 months of free credit monitoring and identity protection through Experian IdentityWorks. The company has also notified law enforcement and continues working with Nebraska DHHS as the state agency responsible for the underlying Medicaid program. Affected individuals should watch for a letter containing an activation code needed to enroll in these protective services.

What Should Affected Individuals Do?

Enroll in Free Credit Monitoring

If you received a notification letter from Maximus, you should enroll in the offered Experian IdentityWorks monitoring service as soon as possible. This service can alert you to new accounts or inquiries opened in your name, which is often the first sign of identity theft.

Because enrollment typically requires an activation code and has a deadline, it helps to act quickly rather than setting the letter aside. Waiting too long could mean missing the window to sign up for this free protection entirely.

Consider a Credit Freeze or Fraud Alert

Since your Social Security number may have been exposed, placing a security freeze with Equifax, Experian, and TransUnion is one of the strongest steps you can take. A freeze blocks new creditors from accessing your credit file, which makes it much harder for anyone to open accounts in your name.

Alternatively, a fraud alert requires creditors to verify your identity before extending credit, offering a lighter but still useful layer of protection. Either option is free to set up, and you can lift a freeze temporarily whenever you need to apply for credit yourself.

Monitor Your Financial Accounts Closely

You should also review your bank and credit card statements regularly for any charges you do not recognize. Because Social Security numbers can be used for purposes beyond simple credit fraud, it also makes sense to watch for unfamiliar tax filings or unexpected government correspondence.

In addition, pulling a free credit report from annualcreditreport.com lets you check for accounts you never opened. Doing this every few months for the next year or two gives you an ongoing picture of your credit health after this incident.

Stay Alert for Phishing Attempts

After a breach like this, scammers sometimes pose as the breached company or a related agency to trick victims into giving up more information. Be cautious of unexpected calls, texts, or emails asking you to confirm personal details or click a link.

Instead, if you want to verify a message’s legitimacy, contact Maximus or Nebraska DHHS directly using contact information from an official source rather than anything provided in the suspicious message itself. This simple habit can prevent a second round of fraud stemming from the original breach.

Report Suspicious Activity and Know Your Options

If you notice signs of identity theft, report them promptly to your state Attorney General, local law enforcement, or the Federal Trade Commission. Filing a report creates an official record that can help you dispute fraudulent charges or accounts later.

Finally, because Maximus was entrusted with sensitive government program data, affected individuals may want to understand what legal options exist. Speaking with a data breach attorney for a free case evaluation can help you determine whether you qualify for compensation tied to this incident.



More Information

Official data breach notification from Hawaii Office of Consumer Protection

Official data breach notification from Delaware Attorney General

Official data breach notification from California Attorney General

Related Data Breaches

Check other recent data breach notifications →