The District of Columbia Department of Human Services (DHS) is committed to protecting customers’ personal information. We are constantly reviewing and strengthening our policies and procedures to protect DHS customer privacy.
DHS maintains rigorous data protection standards aligned with the comprehensive data policy for District government, including:
- Limiting the collection, use, and retention of private identifying information to what is necessary to accomplish the agency’s business purpose and mission.
- Securing confidential data via encryption and additional safeguards such as digital certificates for integrity and non-repudiation.
- Providing access to customer data only to those persons and entities who reasonably require the information to perform their duties.
- Appropriately disposing of or archiving data when no longer needed.
- Training DHS staff on the District’s data policy and how to properly handle and protect customer data and prevent unauthorized access.
DHS’s Office of Program Review, Monitoring, and Investigation (OPRMI) leads our agency’s efforts to prevent fraud, waste, and abuse in the administration of social service programs and to ensure compliance and accountability with applicable Federal and District statutes, regulations, and procedures, including data protection standards.
Recent Data Privacy Incidents
While DHS goes to great lengths to protect customer data, incidents do sometimes occur. The following are recent data privacy incidents that DHS is required to disclose on our website due to the nature of the incident. Affected customers have received written notifications.
We take the need to protect customer information seriously. To protect DHS customer data, we immediately took action to secure our systems; alerted District government officials, database providers, and partners; and have taken steps to improve our data protection procedures, security controls, and employee trainings in an effort to prevent such incidents from happening again.
Where sensitive personal identifying data was involved, we are offering affected customers two years of complimentary identity theft protection services through Identity Theft Guard Solutions, Inc (IDX), a data breach and response expert.
- Operation Make Movement: On July 8, 2026, DHS discovered that between July 1 and July 7, 2026, an unknown person used stolen log-in information from a DHS vendor to access and download data from a DHS database provided by a vendor that was used to process housing voucher applications in 2023, affecting 551 customers. We immediately removed the unauthorized access, performed a full investigation of the incident, and took actions to secure our systems and notify stakeholders. (Written notification to affected customers)
- Taylor Street Service Center: On September 30, 2025, DHS learned that a folder of paper records had been left outside the DHS Economic Security Administration (ESA) Taylor Street Service Center. The folder was left there by a person who no longer works for DHS, and included logs we use to track ESA customer sign ins and what documents are dropped off to be scanned, affecting 314 customers. DHS has recovered the records and is retraining staff on the handling and transport of paper records and changing our procedures so that paper records containing client information are not removed from our facilities. (Written notification to affected customers)
- Medicaid/Public Benefits: On March 4, 2025, DHS initially learned that one or more employees and former employees sent files containing client information to personal email accounts without authorization, affecting 455 customers. In some cases, information was also sent to individuals outside DHS. From the information gathered in our investigation, we believe this activity took place between May 2021 and December 2025. DHS removed the individuals’ access to our systems and is working to recover and confirm the deletion of every copy of the information that was shared without authorization. (Written notification to affected customers)