Were you recently affected by a data breach?

Public Partnerships Data Breach

Public Partnerships, the fiscal intermediary for New York’s CDPAP program, disclosed that a former terminated facilitator may have attempted to sell consumer data to another vendor, potentially exposing personal information for over 12,000 program participants.

Public Partnerships
Date of Breach: June 8, 2026 (disclosed August 7, 2026)
CAU logo

Who was affected:

Clients of Public Partnerships

Impacted Data:

Names, addresses, dates of birth, Medicaid ID numbers, PPL ID numbers, New York Medicaid enrollment status

Public Partnerships, the statewide fiscal intermediary for New York’s Consumer Directed Personal Assistance Program, has disclosed that a former, previously terminated network facilitator may have attempted to sell consumer data to another contracted facilitator.

Companies entrusted with processing Medicaid enrollment and identity information for thousands of program participants have a responsibility to protect that data, including after a vendor relationship with the program has ended.

Public Partnerships’s Data Breach Investigation

On June 8, 2026, Public Partnerships became aware of an allegation that a former network facilitator, previously terminated from the Consumer Directed Personal Assistance Program (CDPAP) for failing to meet program integrity requirements, may have offered to sell access to consumer information to another Public Partnerships-contracted facilitator in New York. The facilitator that received the offer refused it and immediately reported the matter to Public Partnerships.

Upon learning of the allegation, Public Partnerships contacted the New York State Department of Health, which referred the matter to the Office of the New York Attorney General for investigation and enforcement. Public Partnerships also contacted the former facilitator directly, informed it that offering to sell CDPAP consumer data is unlawful and a breach of its ongoing contractual obligations, and instructed it to delete all CDPAP-related data still in its possession.

As an additional precaution, Public Partnerships reminded every remaining network facilitator that buying or selling CDPAP participant data is both illegal and a material violation of their contracts, and that any CDPAP-related information in a facilitator’s possession is confidential and protected under state and federal law.

Public Partnerships reported the incident to the U.S. Department of Health and Human Services Office for Civil Rights, which tracks breaches of protected health information affecting 500 or more individuals. That filing lists roughly 12,018 New York residents as potentially affected. According to Public Partnerships, its investigation to date has found no evidence that any consumer data was actually transmitted, sold, or otherwise misused, though notifications to potentially affected consumers have already begun.

Public Partnerships administers the CDPAP program on behalf of the New York State Department of Health, acting as the statewide fiscal intermediary responsible for processing payroll and maintaining enrollment records for consumers who direct their own home care. That role requires the company and its network of contracted facilitators to handle large volumes of Medicaid enrollment and identity information for a vulnerable population, so any lapse in a terminated vendor’s data-handling practices can put a large number of program participants at risk at once, which appears to be what happened here.

Government assistance programs are an especially attractive target for this kind of misconduct because a single facilitator or vendor can hold identity and benefits information for thousands of enrollees at a time. When Medicaid ID numbers, program enrollment details, and other personal identifiers are combined, that data can be used to file fraudulent benefits claims, open unauthorized lines of credit, or impersonate the affected individual with government agencies and financial institutions. Organizations that administer these programs, along with the network of contracted vendors and facilitators they rely on, carry a heightened responsibility to monitor and restrict data access even after a vendor’s relationship with the program has ended.

Incidents involving a terminated vendor are a particular concern in programs like CDPAP that rely on a large, decentralized network of independent facilitators rather than a single in-house workforce. Once a vendor’s contract ends, an organization generally loses direct day-to-day oversight of how that vendor stores or disposes of any data it collected while under contract, which can leave a gap between termination and full data destruction. This incident illustrates why regulators increasingly expect fiscal intermediaries and similar administrators to build stronger contractual and technical safeguards, such as mandatory data-deletion verification and post-termination audits, into their vendor relationships from the outset rather than relying solely on a departing vendor’s word that data has been destroyed.

Home care programs like CDPAP also serve populations, including elderly and disabled individuals, who can be especially vulnerable to follow-up scams after a breach notification goes out. Fraudsters sometimes use news of a real breach to run copycat phishing calls or letters posing as the company, the state Medicaid office, or a credit-monitoring provider, asking recipients to confirm account details or payment information. Consumers who receive an official notice about this incident should independently verify any follow-up communication through the phone numbers Public Partnerships has published rather than a number or link supplied in an unsolicited message.

When Did This Breach Occur?

Public Partnerships states that it first became aware of the allegation on June 8, 2026, after a contracted facilitator refused an offer to purchase consumer data from the previously terminated vendor and reported it. The company publicly disclosed the incident in an August 7, 2026 statement and began the process of notifying affected CDPAP consumers around that time. The exact date on which the former facilitator obtained or attempted to sell the data has not been made public.

What Information Was Breached?

Public Partnerships states that, to the best of its knowledge, the information that may have been affected includes each consumer’s name, address, date of birth, Medicaid ID number, PPL ID number, and enrollment status in New York Medicaid. The company has not disclosed evidence that this information was actually viewed, copied, or sold by the former facilitator, only that it may have been offered for sale to another contracted vendor.

What You Can Do

  • Enroll in the complimentary identity protection and credit monitoring services Public Partnerships is offering to potentially affected consumers, available through Experian’s customer care team at 877-890-9332.
  • Call the dedicated toll-free number Public Partnerships has set up for this matter, 833-706-5436, Monday through Friday from 8 a.m. to 5 p.m. Eastern time, with any questions.
  • Watch for a separate individual notification letter from Public Partnerships with enrollment instructions for the monitoring services.
  • Review Medicaid statements and any benefits correspondence for unfamiliar activity.
  • Consider placing a fraud alert or credit freeze with the three major credit bureaus if you are concerned about identity theft.
  • Report any suspicious activity involving your Medicaid account or personal information to Public Partnerships and to your healthcare provider or financial institution.

File a Data Breach Lawsuit Against Public Partnerships

Consumers who were notified that their personal information may have been exposed by this incident may have legal options, particularly if they experience identity theft, fraudulent account activity, or other harm as a result. An attorney can help evaluate whether Public Partnerships and its network facilitator met their legal obligations to safeguard sensitive Medicaid and personal identification data.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: June 8, 2026 (disclosed August 7, 2026)
Date of Breach: September 2026
Date of Breach: August 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.