Skip to main content
Jump to a category page

What IHSS and Medi-Cal Clients Need to Know

The Fresno County Department of Social Services has notified an individual that their personal information was exposed after an unauthorized user accessed a sensitive data file. The incident involves clients of the department’s In-Home Supportive Services (IHSS) and Medi-Cal programs.

According to the notice, the Department learned of anomalous unauthorized activity involving an employee on June 2, 2026. Its review determined that the underlying access actually occurred nearly ten months earlier, on August 26, 2025, when an unauthorized user accessed a data file containing sensitive information. The incident was reported to the California Attorney General on July 28, 2026.

A Long Gap Between Access and Disclosure

Two things stand out here. First, the timeline: nearly 11 months passed between the date the county says the data file was actually accessed and the date it reported the incident to the California Attorney General, with the Department’s own discovery of the problem not happening until roughly nine and a half months after the access itself. Second, the notice letter does not offer any credit monitoring, identity protection service, or similar remedy. It points recipients to a general identity theft prevention page and the California Attorney General’s website, nothing more.

What Information Was Exposed?

Per the Department’s notice letter, the exposed information was limited to:

  • First and Last Name
  • Address
  • Client Index Number (CIN) or Medi-Cal Number
  • Phone Number
  • In-Home Supportive Services (IHSS) Case Number

The notice states this information was limited to the person named on the letter; the county has not disclosed how many people in total were affected.

What Is the Department Offering?

Nothing beyond general guidance. The notice recommends contacting the three major credit bureaus to place a fraud alert, reviewing a generic identity theft prevention sheet, and visiting the California Attorney General’s privacy page. No credit monitoring, identity theft insurance, or similar service is being provided to affected individuals.

Your Information Is at Risk, Even Without a Social Security Number

This breach doesn’t involve a Social Security number, but that doesn’t mean the exposed information is low-risk. A Medi-Cal number or IHSS case number tied to a name, address, and phone number can be used to attempt benefits fraud or to impersonate a client when contacting county caseworkers, and many people affected by an IHSS-related breach are elderly or disabled Californians who rely on these programs for essential in-home care, exactly the population that scammers and identity thieves most often target.

Do You Have Legal Options?

Government agencies that collect and store sensitive client information, including Medi-Cal and IHSS case data, have a legal duty to protect it and to notify affected individuals without unreasonable delay. Claims against a county government agency can involve additional procedural steps not required in a typical breach case, so it’s worth talking to an attorney familiar with both data breach law and claims against government entities.

Contact the Data Breach Attorneys at Emery | Reddy today for a Free Case Review.

Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.

Much of the information involved in this incident may also qualify as Protected Health Information (PHI). PHI includes medical or healthcare-related data protected under federal and state privacy laws. When PHI is compromised, it can be misused for medical identity theft or insurance fraud.

Residents of California may be entitled to additional protections under the California Consumer Privacy Act (CCPA), which provides enhanced rights regarding the collection, use, and safeguarding of personal information.

FAQ

How many people were affected by the Fresno County DSS data breach?

Not publicly disclosed. The notice letter and California Attorney General filing don’t state a total population figure.

What information was exposed?

Name, address, phone number, and either a Client Index Number (CIN) or Medi-Cal number, plus an IHSS case number where applicable. No Social Security number was involved, per the notice.

Why did it take so long to be notified?

The county says the data file was accessed on August 26, 2025, but the Department didn’t discover the anomalous activity until June 2, 2026, and didn’t file with the California Attorney General until July 28, 2026, nearly 11 months after the access itself.

Is the county offering credit monitoring?

No. The notice only points recipients to general identity theft prevention resources and the California Attorney General’s website.

"Very friendly interview and intake process. I was informed thoroughly about the processes in obtaining a lawyer and was given ample time to make a decision on representation. I’m thankful for everyone’s help and looking forward to working with this Firm on my worker’s compensation claim."

- Darren A.

Receive a
FREE Case Review

Call Now