Hundreds of members of congress affected by data breach

Over 50,000 current and former members of DC Health Link have been affected by a data breach

Add bookmark
Hundreds of members of congress affected by data breach

DC Health Link, the provider of health insurance for those in the United States (US) Government, has suffered a data breach that affects over 50,000 people. 

The cyber attack, which took place on March 6, saw an unauthorized party gain access to the data of 56,415 current and past customers of DC Health Link, including 585 staff members and 17 members of the US Congress. 

In a message sent to employees on March 8, the US House of Representatives explained that the data breach has “potentially expos[ed] the Personal Identifiable Information (PII) of thousands of enrollees”.  
After the breach was discovered, DC Health Link reported it to the FBI and Google-owned cyber security firm Madinat. Following this, the health insurance company notified six other federal agencies whose employees use DC Health Link for their health insurance. 

Mila Kofman, executive director of DC Health Link, submitted documents ahead of her testimony before the House Oversight Committee on April 19, revealing that the data breach was caused by a misconfigured cloud server.

This misconfiguration was, according to Kofman, caused by human error rather than malicious intentions, and once discovered was shut down immediately by the security manager at DC Health Link. 

When surveyed by Cyber Security Hub, one in four (25 percent) of cyber security professionals said that their companies were investing in cloud security capabilities. As more companies invest in and migrate to the cloud, they should be aware of the risks and ensure that protections are put in place to prevent attacks and breaches.

Matt Kerr, CEO and founder of appliance repair site Appliance Geeked, notes that while the cloud-based data storage can be equipped with cyber security measures to prevent data breaches, if a company hosts a large amount of valuable customer data, even a partial breach can have far-reaching negative effects.

This is because a company’s cloud storage contains “enormous hoards of extraordinarily valuable data”, even if an attacker only gains access to a fraction of this data, they can do real damage with it. 


Upcoming Events

16th Automotive Cybersecurity Summit 2026

March 18 - 19, 2026

Sheraton Ann Arbor Hotel, Ann Arbor, Michigan

16th Automotive Cybersecurity Summit 2026

Digital Identity Week

1st - 2nd September 2026

Sydney, Australia

Digital Identity Week

Latest Webinars

From Dependencies to Defences: Navigating Software Supply Chain Security

2025-09-24

11:00 AM - 12:00 PM SGT

Learn how to defend your software supply chain from dependency threats and build resilient security...

Unpacking global regulatory frameworks to enhance third-party operational resilience

2024-11-14

11:00 AM - 12:00 PM EST

Join this webinar to explore the resilience-focused requirements of DORA, NIS2 and other global regu...

Preventing financial and reputational risk with process intelligence

2024-05-23

11:00 AM - 12:00 PM EDT

Learn how to manage risk stemming from poorly controlled processes in a collaborative way

Recommended

info@cshub.com/r/n

We hope you enjoy All Access from CS Hub!!<\/p>\r\n<p>Best Regards,<\/p>\r\n<p><a href=https://www.cshub.com/"https:////www.cshub.com///" target=\"_blank\">CS Hub Team<\/a><\/p>\r\n<p>P.S. Be sure to check out our other upcoming <a href=https://www.cshub.com/"https:////www.cshub.com//events?filter_format=ONLINE\%22 target=\"_blank\">All Access events here<\/a>.<\/p>\r\n<p>--------------------------------<\/p>\r\nConnect with us on Social Media: <a href=https://www.cshub.com/"https:////www.linkedin.com//groups//12067996///" target=\"_blank\">LinkedIn<\/a> | <a href=https://www.cshub.com/"https:////twitter.com//CSHubUSA/" target=\"_blank\">Twitter<\/a><\/p>\r\n<p>--------------------------------<\/p>\r\n<p>FAQS<\/p>\r\n<p><b>Can I invite my colleagues?<\/b><br>Yes of course! Please send them this link so they can register for free! [WebUrl]<\/p>\r\n\r\n<p><b>How do I access the sessions?<\/b><br>\r\nAll Access is run on Zoom Events. You should receive an email shortly from Zoom Events with your unique All Access link to the event lobby. Please hold on to that email ahead of the event. We\u2019ll also send you a reminder 24 hours before we go live!<\/p>\r\n\r\n<p><b>Will the agenda be updated?<\/b><br>\r\nYes, the agenda will be continuously updated on the website with the latest sessions & speakers. As we get closer to the event, also look out for our weekly updates which will also include the latest updates information and link to access the event.<\/p>\r\n<p><b>Can I access the sessions On Demand?<\/b><br>\r\nEvery session will be available after the event via the event lobby. We\u2019ll also send you a reminder about the On Demand sessions which will be sent to you after the event is over.<\/p>\r\n<p>--------------------------------<\/p>\r\n<p>RELATED RESOURCES TO READ BEFORE YOUR EVENT<\/p>\r\n<ul>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//executive-decisions//reports//cs-hub-mid-year-market-report-2022?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CS Hub Mid-Year Market Report 2022<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//ciso-strategies-for-proactive-threat-prevention?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CISO strategies for proactive threat prevention<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//how-to-strengthen-email-security-and-protection-against-advanced-ransomware-attacks?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">How to strengthen email security and protection against advanced ransomware attacks<\/a><\/li>\r\n<\/ul>","event_registration_srs_confirmation_email":null,"assets_from_cdn":true},"bant_disabled":1,"sponsorship_disclaimer":null,"sponsorship_disclaimer_text":null,"sponsorship_disclaimer_checkbox_disabled":0,"ext_treat_id":null,"recording_url":null,"file_attachment":null,"ingo_enabled":0,"ingo_activator_id":null,"ingo_autofiller_id":null,"ingo_amplifier_id":null,"ingo_authorizer_id":null,"restricted_content":0,"featured_events_embedded":[],"featured_content_embedded":[{"id":"637e48c1038d960407563826","name":"Revising your backup strategy in 2023","description":"How to evaluate the effectiveness of a data backup strategy","file":null,"url":"\/data\/articles\/revising-your-backup-strategy-in-2023"},{"id":"641365b4b04b0666ce20cf7a","name":"What is phishing?","description":"Cyber Security Hub explores the widespread and dangerous practice of phishing attacks and how you can prevent them.","file":null,"url":"\/attacks\/articles\/what-is-phishing"},{"id":"63a1a9a82bae49245b51a94f","name":"The most dangerous cyber security threats of 2023","description":"Cyber security experts share their prediction for the most impactful threat vectors and cyber risks of 2023","file":null,"url":"\/attacks\/articles\/the-most-dangerous-cyber-security-threats-of-2023"},{"id":"63750c0d4e29cc27181bdb09","name":"The four pillars of cloud security","description":"Learn about four keystones of cloud security: accountability, strategy, visibility and enablement","file":null,"url":"\/cloud\/articles\/four-main-pillars-of-cloud-security"},{"id":"63934ace4aac423e0549f5e2","name":"The biggest data breaches and leaks of 2022","description":"The data breaches that had the biggest impact in the cyber security world over the past 12 months","file":null,"url":"\/attacks\/articles\/the-biggest-data-breaches-and-leaks-of-2022"}],"featured_content_portal_embedded":null}" >