A misconfigured server at DC Health Link exposed personal information for tens of thousands of enrollees, including members of Congress, congressional staff, and their families. The stolen data was offered for sale on a public hacking forum.
What happened
In early March 2023, the DC Health Benefit Exchange Authority told enrollees and the public that DC Health Link had been breached. DC Health Link runs the health insurance marketplace for the District, and many congressional staff and their families buy coverage through it. According to reporting from CBS News and others, a misconfigured server let an unauthorized party take enrollee data and post it for sale on a hacking forum. About 56,000 people were affected. Reporting at the time put 21 sitting members of Congress among them, along with hundreds of staff and dependents.
The exposed data included names, home addresses, dates of birth, and Social Security numbers. House leaders said the FBI told them it had purchased samples of the leaked data to confirm what had been taken.
DC Health Link offered affected enrollees three years of free credit monitoring, covering spouses and dependents. The exchange also drew multiple class-action lawsuits over the breach and later agreed to a $1.45 million settlement.
How it started
The breached server held enrollment records going back years. A third-party forensic review by Mandiant traced the cause to a misconfigured server, not a sophisticated attack. The data sat exposed long enough for someone to copy it and offer it for sale.
Members of Congress, congressional staff, and federal employees are a standing target for doxxing. Once a name, home address, and date of birth are on a forum, that kind of data tends to get cross-referenced against people-search and data broker sites and republished there. Broker pages can keep surfacing a home address long after the original forum post is gone.
What this means for you
If you work in federal law enforcement, federal court security, or a sworn role based in DC, your home address may not be sitting on a hacking forum today. It is far more likely to be on a data broker page, scraped from public records and older breach data. DC has no Daniel's Law analog, the kind of statute that lets covered people demand removal from data brokers. The District does run an address confidentiality program, but it is built for victims of domestic violence, sexual assault, stalking, and trafficking, not for sworn personnel generally.
The federal Lieu Act covers federal judges and their immediate families, letting them demand removal of their personal information from data brokers. Most other federal employees have no comparable removal right. A settlement and free credit monitoring do not pull your address off the broker pages. That part still has to be done by hand — send the removal requests, then check back when the brokers repost.
What reduces this risk
A government system you never chose can still put your home address into a data set that gets bought and sold. In the District, federal staff and federal law enforcement have no broker-removal statute of their own, and DC has no Daniel's Law analog. Federal judges are the exception, covered by the Lieu Act. You can still remove what is removable from the brokers, watch the sites that repost it, and file again. That is the work we take on.
Public sources
- DC Health Link data breach blamed on human error — AP News, 2023-04-18
- Following a significant breach, DC Health Link user data is being sold on the dark web — CBS News, 2023-03-08