I don’t usually write articles because I’m angry.
Today is an exception.
Within the past week, I received a notification letter from the North Los Angeles County Regional Center (NLACRC). The letter is dated June 30, 2026, yet it discusses a cybersecurity incident that reportedly occurred between November and December 2024.
Let that timeline sink in for a moment.
We’re not talking about a few weeks or even a few months. We’re talking about well over a year between the reported incident and the notification that finally arrived in my mailbox.
The letter contains the standard language we’ve all come to expect after a data breach. It apologizes for the inconvenience, explains that an incident occurred, provides a telephone number for a call center, and offers guidance on protecting yourself from identity theft and fraud.
But that isn’t what bothers me.
What bothers me is who NLACRC serves.
Regional centers aren’t retailers. They aren’t social media companies. They aren’t online shopping sites.
They serve people with developmental disabilities and their families. Many clients depend on regional centers for services that can include case management, referrals, IHSS coordination, dental assistance, employment and day programs, transportation resources, and many other forms of support.
To receive those services, clients or their families often have to provide highly sensitive personal information.
That creates an obligation to protect that information and, when something goes wrong, to communicate with the people whose information may have been affected.
According to the letter I received, NLACRC discovered suspicious activity in its computer systems on November 28, 2024. The investigation determined there was unauthorized activity between November 20 and December 1, 2024. The letter states that an unauthorized actor copied information before encrypting certain computer systems, a sequence of events consistent with a ransomware attack.
The notification also explains that, in my case, the information that may have been involved includes my name, date of birth, and my UCI number, which is the unique client identification number used by the regional center to identify individuals receiving services. NLACRC’s public Notice of Data Incident states that, depending on the individual, the information involved could also include addresses, telephone numbers, Social Security numbers, email addresses, financial account information, payment card information, health insurance information, medical information, diagnoses, treatment information, disability-related information, and other personal identifiers.
People who receive services from a regional center often don’t have the luxury of simply taking their business somewhere else. They rely on these organizations because they need the services they provide. That makes protecting personal information, and communicating openly when something goes wrong, even more important.
As a client, I have questions.
- Why did it take so long for this notification to arrive?
- When did NLACRC determine that client information had been accessed?
- How many people were affected?
- What security improvements have been made since the incident?
- What additional information can clients expect as the investigation continues?
- Most importantly, what should clients be doing today to protect themselves?
I’m not writing this article to accuse anyone of wrongdoing. Cybersecurity investigations can be lengthy and complex, and there may be facts that are not yet publicly known.
However, I believe clients deserve timely communication.
When an organization serves people with disabilities, trust is one of its most valuable assets. Clients or their families often have little choice but to share personal information because that is how services are provided.
Learning about a possible exposure of that information more than a year after the reported incident doesn’t inspire confidence. It raises serious questions about communication, transparency, and how organizations respond when the people they serve may be at risk.
This situation also highlights a larger issue that extends beyond a single organization.
Data breaches have become so common that many people almost expect them. Banks, retailers, healthcare providers, schools, government agencies, nonprofit organizations, and organizations serving people with disabilities have all experienced cybersecurity incidents. While no organization can guarantee it will never become the next victim, every organization can control how it responds once an incident is discovered.
For organizations serving the disability community, communication is especially important. Many clients rely on regional centers for essential services and may not regularly follow cybersecurity news. Some depend on family members, caregivers, or advocates to help manage important correspondence. Delayed notifications reduce the amount of time people have to monitor financial accounts, review credit reports, change passwords, place fraud alerts, freeze their credit, or take other protective measures.
Whether you are directly affected by this incident or simply reading about it, this serves as another reminder to remain vigilant. Review your financial statements, monitor your credit reports, use strong and unique passwords, enable multi-factor authentication wherever possible, and be cautious of unexpected phone calls, emails, or text messages referencing this incident. Cybercriminals frequently use publicized breaches to launch convincing phishing campaigns against people who are already concerned about their personal information.
One thing I also noticed is that, as of this writing, this incident does not yet appear in Have I Been Pwned’s list of tracked breached websites. That doesn’t mean the incident didn’t happen or that the data won’t eventually appear there. Breach tracking services update on their own schedules, and not every incident results in a publicly searchable dataset. Still, it’s something I’ll be watching with interest.
I hope NLACRC continues to provide answers to the people it serves. Clients deserve to understand what happened, what information may have been affected, what additional protections have been put in place since the incident, and what guidance may become available as the investigation continues.
As someone who depends on NLACRC services, I don’t expect perfection. Cyberattacks can happen to any organization. What I do expect is timely communication, transparency, and clear answers when something this significant affects the people an organization exists to serve.
Until then, I encourage anyone who receives one of these letters to read it carefully, take advantage of any assistance being offered, monitor their accounts, consider placing a fraud alert or credit freeze if appropriate, and remain alert for signs of identity theft or fraud.
No one expects an organization to be perfect. There is no such thing anymore.
But transparency is the key.
Resources
Related
Discover more from Jared's Technology podcast network
Subscribe to get the latest posts sent to your email.
When a Breach Hits the Disability Community, Time Matters
I don’t usually write articles because I’m angry.
Today is an exception.
Within the past week, I received a notification letter from the North Los Angeles County Regional Center (NLACRC). The letter is dated June 30, 2026, yet it discusses a cybersecurity incident that reportedly occurred between November and December 2024.
Let that timeline sink in for a moment.
We’re not talking about a few weeks or even a few months. We’re talking about well over a year between the reported incident and the notification that finally arrived in my mailbox.
The letter contains the standard language we’ve all come to expect after a data breach. It apologizes for the inconvenience, explains that an incident occurred, provides a telephone number for a call center, and offers guidance on protecting yourself from identity theft and fraud.
But that isn’t what bothers me.
What bothers me is who NLACRC serves.
Regional centers aren’t retailers. They aren’t social media companies. They aren’t online shopping sites.
They serve people with developmental disabilities and their families. Many clients depend on regional centers for services that can include case management, referrals, IHSS coordination, dental assistance, employment and day programs, transportation resources, and many other forms of support.
To receive those services, clients or their families often have to provide highly sensitive personal information.
That creates an obligation to protect that information and, when something goes wrong, to communicate with the people whose information may have been affected.
According to the letter I received, NLACRC discovered suspicious activity in its computer systems on November 28, 2024. The investigation determined there was unauthorized activity between November 20 and December 1, 2024. The letter states that an unauthorized actor copied information before encrypting certain computer systems, a sequence of events consistent with a ransomware attack.
The notification also explains that, in my case, the information that may have been involved includes my name, date of birth, and my UCI number, which is the unique client identification number used by the regional center to identify individuals receiving services. NLACRC’s public Notice of Data Incident states that, depending on the individual, the information involved could also include addresses, telephone numbers, Social Security numbers, email addresses, financial account information, payment card information, health insurance information, medical information, diagnoses, treatment information, disability-related information, and other personal identifiers.
People who receive services from a regional center often don’t have the luxury of simply taking their business somewhere else. They rely on these organizations because they need the services they provide. That makes protecting personal information, and communicating openly when something goes wrong, even more important.
As a client, I have questions.
I’m not writing this article to accuse anyone of wrongdoing. Cybersecurity investigations can be lengthy and complex, and there may be facts that are not yet publicly known.
However, I believe clients deserve timely communication.
When an organization serves people with disabilities, trust is one of its most valuable assets. Clients or their families often have little choice but to share personal information because that is how services are provided.
Learning about a possible exposure of that information more than a year after the reported incident doesn’t inspire confidence. It raises serious questions about communication, transparency, and how organizations respond when the people they serve may be at risk.
This situation also highlights a larger issue that extends beyond a single organization.
Data breaches have become so common that many people almost expect them. Banks, retailers, healthcare providers, schools, government agencies, nonprofit organizations, and organizations serving people with disabilities have all experienced cybersecurity incidents. While no organization can guarantee it will never become the next victim, every organization can control how it responds once an incident is discovered.
For organizations serving the disability community, communication is especially important. Many clients rely on regional centers for essential services and may not regularly follow cybersecurity news. Some depend on family members, caregivers, or advocates to help manage important correspondence. Delayed notifications reduce the amount of time people have to monitor financial accounts, review credit reports, change passwords, place fraud alerts, freeze their credit, or take other protective measures.
Whether you are directly affected by this incident or simply reading about it, this serves as another reminder to remain vigilant. Review your financial statements, monitor your credit reports, use strong and unique passwords, enable multi-factor authentication wherever possible, and be cautious of unexpected phone calls, emails, or text messages referencing this incident. Cybercriminals frequently use publicized breaches to launch convincing phishing campaigns against people who are already concerned about their personal information.
One thing I also noticed is that, as of this writing, this incident does not yet appear in Have I Been Pwned’s list of tracked breached websites. That doesn’t mean the incident didn’t happen or that the data won’t eventually appear there. Breach tracking services update on their own schedules, and not every incident results in a publicly searchable dataset. Still, it’s something I’ll be watching with interest.
I hope NLACRC continues to provide answers to the people it serves. Clients deserve to understand what happened, what information may have been affected, what additional protections have been put in place since the incident, and what guidance may become available as the investigation continues.
As someone who depends on NLACRC services, I don’t expect perfection. Cyberattacks can happen to any organization. What I do expect is timely communication, transparency, and clear answers when something this significant affects the people an organization exists to serve.
Until then, I encourage anyone who receives one of these letters to read it carefully, take advantage of any assistance being offered, monitor their accounts, consider placing a fraud alert or credit freeze if appropriate, and remain alert for signs of identity theft or fraud.
No one expects an organization to be perfect. There is no such thing anymore.
But transparency is the key.
Resources
Share this:
Like this:
Related
Discover more from Jared's Technology podcast network
Subscribe to get the latest posts sent to your email.
Published in article commentary, musings and security news and commentary