dbHMS Data Breach Exposes Social Security Numbers and Medical Information

Manufacturing data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: August 2026

What Happened in the dbHMS Data Breach?

dbHMS is a Chicago-based engineering firm that designs mechanical, electrical, and plumbing systems for commercial and institutional buildings. The company operates under the legal name Nest Builders, Inc. In August 2026, it began sending letters to individuals whose personal information may have been caught up in a cybersecurity incident.

According to a notice filed with the Massachusetts Attorney General’s Office, the firm found that an unauthorized party had gained access to its systems. The filing lists the types of data involved but stops short of explaining how the intrusion happened. It also does not state when the incident was first discovered or how many people nationwide were affected.

Because the notice is thin on technical detail, much about the intrusion itself remains unclear. However, this is not unusual. Firms often spend weeks or months confirming exactly whose records were touched before they send any notification letters. As a result, the date printed on a letter frequently trails the actual intrusion by a significant stretch of time.

What is confirmed is that dbHMS treated the incident seriously enough to notify a state regulator and offer paid identity protection. This step signals that its internal review found real evidence of unauthorized access to sensitive files, not simply a suspected or attempted intrusion.

Who was affected?

The notification describes the affected group simply as clients of dbHMS. Because the firm works with commercial and institutional building owners, this group could include property managers, facility staff, and other individuals connected to those client organizations.

The total number of people affected nationwide has not been publicly disclosed. Firms in the architecture, engineering, and construction space often hold personnel-style records for contractors and institutional partners alongside their direct clients. This means the affected population could extend beyond people who think of themselves as customers in a traditional sense.

Because medical information was involved, it is possible that some affected individuals had health-related records on file for reasons connected to workplace safety, insurance, or project administration. At this stage, dbHMS has not clarified whether minors could be among those affected.

What Information Was Potentially Exposed?

The notification letter identifies several categories of personal data that may have been accessed without authorization. This combination of information is considered highly sensitive because it goes well beyond a name and email address.

  • Full names
  • Social Security numbers
  • Driver’s license numbers
  • State-issued identification card numbers
  • Passport information
  • Other government-issued identification
  • Medical information

This mix of data creates several distinct avenues for misuse. For example, a stolen Social Security number paired with a name can allow criminals to open new credit accounts or file fraudulent tax returns in someone else’s name. Because driver’s license and passport details were also involved, thieves could attempt to create fake identification documents or pass identity checks that rely on those numbers.

Medical information adds another layer of risk. Criminals sometimes use stolen medical details to submit fraudulent insurance claims or obtain prescription medications under someone else’s name. This type of fraud can be especially damaging because it may alter a victim’s medical records, potentially affecting future treatment decisions. Given how long stolen data can remain in circulation, affected individuals should assume the risk extends well past any free monitoring period.

What is the company doing?

dbHMS reports that it is offering complimentary credit monitoring through Equifax to individuals affected by the incident. The company has also provided guidance in its notification letters about placing fraud alerts and credit freezes.

In addition, the firm filed formal notice with the Massachusetts Attorney General’s Office, a step required under that state’s breach notification law once a company determines residents’ personal information was accessed without authorization. This filing indicates dbHMS has already completed at least a preliminary internal investigation into the scope of the incident.

Going forward, affected individuals should watch for any updates from dbHMS regarding the enrollment deadline for credit monitoring. Because the company has not disclosed further technical details publicly, additional information may still emerge as its review continues.

What Should Affected Individuals Do?

Enroll in Credit Monitoring Promptly

If you received a letter from dbHMS, sign up for the complimentary Equifax monitoring service as soon as possible. Enrollment windows are often limited, so acting quickly helps ensure you don’t miss the deadline.

Credit monitoring won’t undo any exposure that already occurred. However, it can alert you quickly if someone tries to open new accounts using your information, which gives you a better chance to limit the damage.

Consider a Credit Freeze or Fraud Alert

Because Social Security numbers and government identification numbers were involved, placing a credit freeze with Equifax, Experian, and TransUnion is a strong protective step. A freeze blocks new creditors from accessing your credit file, which makes it much harder for a thief to open accounts in your name.

Alternatively, a fraud alert requires lenders to take extra steps to verify your identity before extending credit. This option is less restrictive than a freeze but still adds a meaningful layer of protection. Either way, request your free credit reports at annualcreditreport.com so you can check for accounts you don’t recognize.

Watch Closely for Medical Identity Theft

Because medical information was part of this incident, review any insurance statements or medical bills carefully in the coming months. Look for unfamiliar provider names, unexpected charges, or claims for services you never received.

If you spot anything suspicious, contact your health insurer immediately to dispute the claim. You should also request a copy of your medical records to confirm nothing has been altered without your knowledge.

Stay Alert for Phishing Attempts

Scammers often use breach news to craft convincing phishing emails or phone calls that pretend to come from the breached company or a credit bureau. Because your name and other identifying details were exposed, any future contact attempting to


Related Data Breaches

See the latest data breaches we're tracking →