Maximus US Services, Inc., a subsidiary of government services contractor Maximus, Inc., has disclosed a data security incident affecting the Nebraska Provider Data Management System (PDMS), a platform Maximus operates on behalf of the Nebraska Department of Health and Human Services (NE DHHS) for its Medicaid program. Companies entrusted with sensitive government data have a responsibility to protect it, and individuals affected by this incident deserve to understand what happened and what options may be available to them.
Maximus’s Data Breach Investigation
Maximus operates the PDMS, the system Nebraska Medicaid providers must be enrolled in to render services to program beneficiaries. On April 27, 2026, Maximus discovered a security incident involving this system and immediately began an internal investigation. That same day, the company notified NE DHHS of the incident, and it provided the state agency with additional information the following day, April 28, 2026. Maximus has stated that it worked cooperatively with NE DHHS throughout the process that followed.
To determine the scope of the incident, Maximus engaged an outside forensic firm to examine the affected systems. That investigation concluded on June 16, 2026, when Maximus determined that personal information belonging to certain individuals may have been accessed without authorization. Maximus began sending written notification letters to affected individuals on July 10, 2026, informing them of the incident and the steps being taken in response, including notifying law enforcement.
Incidents involving government contractors that manage large provider or beneficiary databases are an increasingly common target for unauthorized access, since these systems often centralize identifying information for thousands of individuals across a state program in a single location. When a Social Security number is exposed alongside a full name and date of birth, as is the case here, the combination is often enough on its own to allow someone to open new lines of credit, file a fraudulent tax return, or otherwise impersonate the affected person, even without any additional financial account information being compromised.
Maximus has not publicly disclosed the total number of individuals affected by this incident, nor has the company stated a specific cause, such as a ransomware attack or phishing compromise, for how the unauthorized access occurred. The notification letter sent to affected individuals does not identify a threat actor or describe the technical nature of the intrusion. What is known is that the company took several weeks between initial discovery of the incident and the completion of its forensic review, which is a common timeline for organizations working to accurately determine which individuals and what categories of data were actually affected before notifying anyone.
Contractors that operate government benefit-eligibility and provider-enrollment systems are also frequently subject to state and federal data security requirements as a condition of their contracts, meaning an incident like this one can draw scrutiny not only from affected individuals but also from the government agencies whose programs rely on the compromised system. Individuals whose information was included in the Nebraska PDMS at the time of the incident should treat any notification they receive from Maximus seriously and take the recommended protective steps promptly.
When Did This Breach Occur?
Maximus learned of the security incident affecting the Nebraska PDMS on April 27, 2026. The company reported the incident to Nebraska DHHS that same day and provided supplemental details the following day. Following a forensic investigation, Maximus determined on June 16, 2026, that personal information had potentially been impacted, and it began mailing notification letters to affected individuals on July 10, 2026.
What Information Was Breached?
According to Maximus’s notification letter, the information that may have been impacted includes affected individuals’ first and last names, dates of birth, and Social Security numbers. Maximus has not disclosed whether any additional categories of information, such as financial account numbers or medical information, were involved in the incident.
What You Can Do
Maximus is offering affected individuals 24 months of free credit monitoring and identity protection services through Experian IdentityWorks. Those who received a letter should enroll before the stated deadline and take the following steps:
- Enroll in the free credit monitoring service using the activation code provided in your notification letter
- Regularly review your bank and credit card statements for unauthorized activity
- Consider placing a fraud alert or security freeze with Equifax, Experian, and TransUnion
- Obtain a free copy of your credit report at annualcreditreport.com and review it for unfamiliar accounts
- Report any signs of identity theft to your state Attorney General, local law enforcement, or the Federal Trade Commission
File a Data Breach Lawsuit Against Maximus
If your personal information was exposed as a result of this incident involving Maximus and the Nebraska Provider Data Management System, you may have legal options available to you. Companies that manage sensitive personal information, including on behalf of government programs, are expected to maintain reasonable safeguards to prevent unauthorized access.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.