Fresno County Department of Social Services Data Breach

The Fresno County Department of Social Services (DSS) has sent out a data breach notification letter after discovering that an employee accessed a file containing sensitive client information without authorization. If you received this letter, it means your information was found in that file, and the county wants you to understand what happened and what you can do about it.

According to the notice, DSS learned on June 2, 2026 of anomalous activity involving an employee. After reviewing the situation, the department determined that the actual unauthorized access to the data file took place earlier, on August 26, 2025. The department says it has no indication, as of the date of the letter, that anyone’s personal information has actually been misused. That’s a meaningful point, but it doesn’t mean the risk is zero, especially given the type of information involved.

What information was involved?

The letter states that the exposed information was limited to the following, and only for the person named on the letter:

  • First and last name
  • Address
  • Phone number
  • Client Index Number (CIN) or Medi-Cal Number
  • In Home Supportive Services (IHSS) Case Number

This combination is more sensitive than a typical name-and-address leak. A Medi-Cal number can function like an insurance or health-benefits ID, and an IHSS case number is tied directly to a person’s in-home care services. Together with your name, address, and phone number, this information could potentially be used to impersonate you when dealing with health, insurance, or social services systems, or to attempt fraud tied to your benefits.

Who is affected?

The letter is addressed to a specific individual whose data appeared in the accessed file, so this notice was sent because your information specifically was involved. The department has not indicated how many other people, if any, were affected by the same incident.

What is the department doing?

Fresno County DSS says the incident was reported to appropriate authorities and is currently under investigation. The letter does not mention any free credit monitoring or identity protection service being offered to affected individuals. If that changes, any update would typically come as a follow-up letter or notice from the department.

What should you do now?

Because Medi-Cal and case-specific identifiers were involved, it’s worth taking this seriously even though there’s no confirmed misuse yet. Here’s a practical checklist:

  • Place a fraud alert with one of the three major credit bureaus (Equifax, Experian, or TransUnion). A fraud alert is free, lasts 90 days, and makes it harder for someone to open new credit in your name; the bureau you contact is required to notify the other two.
  • Request a free copy of your credit report at annualcreditreport.com and look for any accounts or inquiries you don’t recognize.
  • Contact your healthcare provider or health plan and request a copy of your medical records or health history as a baseline, so you can later spot any inconsistencies that might suggest your Medi-Cal information was misused.
  • If you notice suspicious activity, file an identity theft report with local law enforcement — Fresno Police if you live in the city, or the Fresno County Sheriff’s Department elsewhere in the county.
  • Consider contacting the DMV Fraud Hotline (1-866-658-5758) to place a fraud alert on your driver’s license, since identity thieves sometimes use stolen personal details this way.
  • Given that health and case-related identifiers were exposed, it may also help to consider signing up for a service like Aura or LifeLock, which can alert you if your information appears elsewhere or is being used in ways you wouldn’t expect.
  • Keep the original notice letter and any related correspondence in a safe place — you may need it as documentation if you ever have to dispute fraudulent activity.
  • If you have questions specific to this incident, the letter lists Division Chief Elsa Bustos at (559) 600-5401, referencing incident number 26-0473.

Watching your accounts and health records over the coming months, rather than assuming a single check is enough, gives you the best chance of catching any misuse early.

Leave a Comment