Fresno County Department of Social Services Data Breach Exposes Medi-Cal and Client Case Information

Non-profit data breach illustration
Breach Discovery: June 2026Breach Notification: July 2026

What Happened in the Fresno County Department of Social Services Data Breach?

County officials in Fresno, California, sent formal notice to a group of residents this month after finding that a staff member had reached into a file well beyond the scope of their job duties. The Fresno County Department of Social Services confirmed that one of its own employees viewed a data file holding sensitive client records without permission to do so. This kind of insider access case often gets less attention than a headline-grabbing hack, but it can carry the same real consequences for the people whose information was involved.

Based on the notification letter filed with the California Attorney General, the department pinpointed the unauthorized access to a single data file that had taken place in August 2025. However, county staff did not detect any sign of a problem until roughly nine months later. As a result, the timeline here looks different from a typical outside cyberattack, where automated monitoring tools sometimes catch intrusions within hours or days.

Once anomalous activity involving the employee came to light in June 2026, the department launched an internal review to figure out exactly what had been accessed and who was affected. That review led investigators to conclude that the exposure was limited to a specific file rather than a broad systemwide compromise. The department also referred the matter to outside authorities, who are now conducting their own separate investigation into the incident.

Because this was an internal access issue rather than a hack from outside, the department’s notification obligations still applied. Agencies that manage public benefits programs are required to act once they learn that client data may have been viewed without authorization. The county has stated it has no current evidence that anyone misused the information, but it chose to notify people out of caution rather than wait for proof of harm.

Who was affected?

The people affected by this breach are clients who rely on Fresno County’s social services programs. This includes individuals connected to In-Home Supportive Services, known as IHSS, as well as those with Medi-Cal casework tied to the county. Because these programs serve elderly residents, people with disabilities, and low-income families, the population affected may include some of the county’s most vulnerable residents.

The department has not made public a specific number of individuals affected by this incident. Instead, notification letters appear to have gone out on an individualized basis, meaning each letter reflects the specific data tied to that one person rather than a shared list. This suggests the county was able to isolate exactly whose records the employee accessed, though the overall scope has not been disclosed publicly.

It is worth noting that participation in a program like IHSS or Medi-Cal can itself be considered sensitive information. Many people prefer to keep their reliance on public assistance private for reasons that go beyond typical identity theft concerns. This breach, therefore, raises privacy considerations that extend past the usual financial fraud risk discussion.

What Information Was Potentially Exposed?

According to the county’s own notification letter, the data file an unauthorized employee accessed contained several categories of personal and case-related information. While no Social Security numbers or financial account details were named in the disclosure, the combination of identifiers involved is still sensitive.

  • First and last name
  • Home address
  • Phone number
  • Client Index Number (CIN) or Medi-Cal number
  • In-Home Supportive Services (IHSS) case number

Even though this list does not include a Social Security number, it still creates a meaningful risk. Someone with a person’s name, address, and case number could impersonate that individual when contacting benefits offices. For example, a bad actor might call claiming to be the client in order to request a change to an active case or redirect benefit payments.

In addition, this type of data can fuel convincing phishing attempts. A scammer who references a real IHSS case number or Medi-Cal number in a phone call or text message can sound legitimate to an unsuspecting recipient. Because of this, affected individuals should treat any unexpected contact referencing their case details with real suspicion, even if the caller seems to know accurate details about their situation.

What is the company doing?

Once the department confirmed the scope of the unauthorized access, it moved to notify the individuals whose files were involved. The notification letter was filed with the California Attorney General’s Office under incident number 26-0473, which is a standard step for breaches affecting California residents. This filing also made the incident a matter of public record.

Beyond notification, the county reported the matter to appropriate outside authorities, who are now investigating independently. The department has stated that it currently has no indication the accessed information has been misused. Still, because internal access cases can be harder to fully audit than external hacks, this investigation may take time to reach a final conclusion. The county has also included identity theft risk-reduction guidance with the notification letters sent to affected clients.

What Should Affected Individuals Do?

Monitor Your Accounts and Case Activity

Anyone who received a notice from Fresno County should keep a close eye on their financial accounts in the weeks ahead. Look for charges you don’t recognize or unexpected account changes. Even small, unfamiliar transactions can be an early warning sign worth investigating right away.

In addition, pay attention to any communication from the county regarding your IHSS or Medi-Cal case. If you notice unexpected changes to your case status, benefit amount, or contact information on file, report it to the department immediately. Catching a fraudulent change early can prevent a bigger disruption to your benefits later.

Be Skeptical of Unsolicited Contact

Because your case number and personal details may have been exposed, be cautious if someone contacts you out of the blue referencing your Medi-Cal or IHSS case. Scammers often use real details to sound credible, so familiarity with your information doesn’t guarantee legitimacy. Never confirm or provide additional personal information to a caller you didn’t contact first.

If you’re unsure whether a call or message is genuine, hang up and contact the department directly using a phone number you find independently. This simple step can prevent you from accidentally handing over more sensitive information to a scammer posing as a county representative.

Watch for Signs of Identity Theft

Although this breach did not include Social Security numbers, identity thieves can still combine your name, address, and phone number with other leaked data from unrelated sources. Therefore, it remains wise to check your credit reports periodically for unfamiliar accounts or inquiries. You’re entitled to a free credit report from each major bureau once a year through annualcreditreport.com.

If you do spot suspicious activity, act quickly. Report it to the relevant financial institution, and consider filing a report with the Federal Trade Commission at identitytheft.gov. Prompt action can limit the damage and make it easier to dispute fraudulent charges later.

Consider Consulting a Data Breach Attorney

Because government agencies that hold sensitive case information have a duty to protect it, affected individuals may have legal options worth exploring. A data breach attorney can review your specific situation and explain whether you may be eligible to join a claim related to this incident. Many attorneys offer a free initial case evaluation, so there is little downside to asking questions.

Keep your notification letter in a safe place, since it may serve as important documentation if you decide to pursue a claim. This letter, along with any evidence of suspicious activity tied to your case, can help establish a record if you later need to demonstrate harm.



More Information

Official data breach notification from California Attorney General

Related Data Breaches

Browse all recent data breaches →