Were you recently affected by a data breach?

Maximus Data Breach

Maximus, a government services contractor, disclosed a security incident involving Nebraska’s Medicaid Provider Data Management System. Names, dates of birth, and Social Security numbers of enrolled healthcare providers may have been exposed. Affected individuals are being offered free credit monitoring and should remain alert for identity theft.

Maximus
Date of Breach: April 27, 2026
CAU logo

Who was affected:

Clients of Maximus

Impacted Data:

Full names, dates of birth, Social Security numbers

Maximus US Services, Inc., a subsidiary of government services contractor Maximus, Inc., has disclosed a data security incident affecting the Nebraska Provider Data Management System (PDMS), a platform Maximus operates on behalf of the Nebraska Department of Health and Human Services (NE DHHS) for its Medicaid program. Companies entrusted with sensitive government data have a responsibility to protect it, and individuals affected by this incident deserve to understand what happened and what options may be available to them.

Maximus’s Data Breach Investigation

Maximus operates the PDMS, the system Nebraska Medicaid providers must be enrolled in to render services to program beneficiaries. On April 27, 2026, Maximus discovered a security incident involving this system and immediately began an internal investigation. That same day, the company notified NE DHHS of the incident, and it provided the state agency with additional information the following day, April 28, 2026. Maximus has stated that it worked cooperatively with NE DHHS throughout the process that followed.

To determine the scope of the incident, Maximus engaged an outside forensic firm to examine the affected systems. That investigation concluded on June 16, 2026, when Maximus determined that personal information belonging to certain individuals may have been accessed without authorization. Maximus began sending written notification letters to affected individuals on July 10, 2026, informing them of the incident and the steps being taken in response, including notifying law enforcement.

Incidents involving government contractors that manage large provider or beneficiary databases are an increasingly common target for unauthorized access, since these systems often centralize identifying information for thousands of individuals across a state program in a single location. When a Social Security number is exposed alongside a full name and date of birth, as is the case here, the combination is often enough on its own to allow someone to open new lines of credit, file a fraudulent tax return, or otherwise impersonate the affected person, even without any additional financial account information being compromised.

Maximus has not publicly disclosed the total number of individuals affected by this incident, nor has the company stated a specific cause, such as a ransomware attack or phishing compromise, for how the unauthorized access occurred. The notification letter sent to affected individuals does not identify a threat actor or describe the technical nature of the intrusion. What is known is that the company took several weeks between initial discovery of the incident and the completion of its forensic review, which is a common timeline for organizations working to accurately determine which individuals and what categories of data were actually affected before notifying anyone.

Contractors that operate government benefit-eligibility and provider-enrollment systems are also frequently subject to state and federal data security requirements as a condition of their contracts, meaning an incident like this one can draw scrutiny not only from affected individuals but also from the government agencies whose programs rely on the compromised system. Individuals whose information was included in the Nebraska PDMS at the time of the incident should treat any notification they receive from Maximus seriously and take the recommended protective steps promptly.

When Did This Breach Occur?

Maximus learned of the security incident affecting the Nebraska PDMS on April 27, 2026. The company reported the incident to Nebraska DHHS that same day and provided supplemental details the following day. Following a forensic investigation, Maximus determined on June 16, 2026, that personal information had potentially been impacted, and it began mailing notification letters to affected individuals on July 10, 2026.

What Information Was Breached?

According to Maximus’s notification letter, the information that may have been impacted includes affected individuals’ first and last names, dates of birth, and Social Security numbers. Maximus has not disclosed whether any additional categories of information, such as financial account numbers or medical information, were involved in the incident.

What You Can Do

Maximus is offering affected individuals 24 months of free credit monitoring and identity protection services through Experian IdentityWorks. Those who received a letter should enroll before the stated deadline and take the following steps:

  • Enroll in the free credit monitoring service using the activation code provided in your notification letter
  • Regularly review your bank and credit card statements for unauthorized activity
  • Consider placing a fraud alert or security freeze with Equifax, Experian, and TransUnion
  • Obtain a free copy of your credit report at annualcreditreport.com and review it for unfamiliar accounts
  • Report any signs of identity theft to your state Attorney General, local law enforcement, or the Federal Trade Commission

File a Data Breach Lawsuit Against Maximus

If your personal information was exposed as a result of this incident involving Maximus and the Nebraska Provider Data Management System, you may have legal options available to you. Companies that manage sensitive personal information, including on behalf of government programs, are expected to maintain reasonable safeguards to prevent unauthorized access.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: May 13, 2026 to May 14, 2026
Date of Breach: April 30, 2026 to May 7, 2026
Date of Breach: February 21, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.