WASHINGTON — A top House official said that a “significant data breach” at the health insurance marketplace for Washington, D.C., on Tuesday potentially exposed personal identifiable information of hundreds of lawmakers and staff.
In a letter obtained by NBC News, Chief Administrative Officer Catherine L. Szpindor said Wednesday that the U.S. Capitol Police and the FBI had alerted her to a data breach at DC Health Link, the Affordable Care Act online marketplace that administers health care plans for members of Congress and certain Capitol Hill staff.
“Currently, I do not know the size and scope of the breach, but have been informed by the Federal Bureau of Investigation (FBI) that account information and [personally identifiable information] of hundreds of Member and House staff were stolen,” Szpindor said. “I expect to have access to the list of impacted enrollees later today and will notify you directly if your information was compromised.”
Szpindor added that it did not appear that House lawmakers were “the specific target of the attack” on DC Health Link.
A reporter for Punchbowl News first reported on Szpindor’s letter.
The data breach has also affected Senate offices, according to an email sent to Senate offices Wednesday afternoon that said the Senate Sergeant at Arms was informed by law enforcement about a data breach.
The notice said that the “data included the full names, date of enrollment, relationship (self, spouse, child), and email address, but no other Personally Identifiable Information (PII).”
A spokesperson for the DC Health Benefit Exchange Authority, which operates DC Health Link, said Wednesday that it had launched an investigation into the breach.
“We have initiated a comprehensive investigation and are working with forensic investigators and law enforcement. Concurrently, we are taking action to ensure the security and privacy of our users’ personal information,” the spokesperson said in a statement. “We are in the process of notifying impacted customers and will provide identity and credit monitoring services.”
Credit monitoring services were also being provided for all affected customers, the spokesperson said.
The FBI and Capitol Police did not immediately respond to requests for comment.
Out of an “abundance of caution,” Szpindor said, lawmakers may opt to freeze family credit at three major credit bureaus, Equifax, Experian and Transunion.
According to Szpindor’s letter, House Speaker Kevin McCarthy, R-Calif., and House Minority Leader Hakeem Jeffries, D-N.Y., requested additional information from DC Health Link on what data was taken, who was affected and what steps were being taken to protect House victims of the breach.
The House Administration Committee tweeted that panel chairman Bryan Steil, R-Wis., was aware of the data breach “and is working with the [chief administrative officer] to ensure the vendor takes necessary steps to protect the PII of any impacted member, staff, and their families.”