Press "Enter" to skip to content

When a Breach Hits the Disability Community, Time Matters

I don’t usually write articles because I’m angry.

Today is an exception.

Within the past week, I received a notification letter from the North Los Angeles County Regional Center (NLACRC). The letter is dated June 30, 2026, yet it discusses a cybersecurity incident that reportedly occurred between November and December 2024.

Let that timeline sink in for a moment.

We’re not talking about a few weeks or even a few months. We’re talking about well over a year between the reported incident and the notification that finally arrived in my mailbox.

The letter contains the standard language we’ve all come to expect after a data breach. It apologizes for the inconvenience, explains that an incident occurred, provides a telephone number for a call center, and offers guidance on protecting yourself from identity theft and fraud.

But that isn’t what bothers me.

What bothers me is who NLACRC serves.

Regional centers aren’t retailers. They aren’t social media companies. They aren’t online shopping sites.

They serve people with developmental disabilities and their families. Many clients depend on regional centers for services that can include case management, referrals, IHSS coordination, dental assistance, employment and day programs, transportation resources, and many other forms of support.

To receive those services, clients or their families often have to provide highly sensitive personal information.

That creates an obligation to protect that information and, when something goes wrong, to communicate with the people whose information may have been affected.

According to the letter I received, NLACRC discovered suspicious activity in its computer systems on November 28, 2024. The investigation determined there was unauthorized activity between November 20 and December 1, 2024. The letter states that an unauthorized actor copied information before encrypting certain computer systems, a sequence of events consistent with a ransomware attack.

The notification also explains that, in my case, the information that may have been involved includes my name, date of birth, and my UCI number, which is the unique client identification number used by the regional center to identify individuals receiving services. NLACRC’s public Notice of Data Incident states that, depending on the individual, the information involved could also include addresses, telephone numbers, Social Security numbers, email addresses, financial account information, payment card information, health insurance information, medical information, diagnoses, treatment information, disability-related information, and other personal identifiers.

People who receive services from a regional center often don’t have the luxury of simply taking their business somewhere else. They rely on these organizations because they need the services they provide. That makes protecting personal information, and communicating openly when something goes wrong, even more important.

As a client, I have questions.

  • Why did it take so long for this notification to arrive?
  • When did NLACRC determine that client information had been accessed?
  • How many people were affected?
  • What security improvements have been made since the incident?
  • What additional information can clients expect as the investigation continues?
  • Most importantly, what should clients be doing today to protect themselves?

I’m not writing this article to accuse anyone of wrongdoing. Cybersecurity investigations can be lengthy and complex, and there may be facts that are not yet publicly known.

However, I believe clients deserve timely communication.

When an organization serves people with disabilities, trust is one of its most valuable assets. Clients or their families often have little choice but to share personal information because that is how services are provided.

Learning about a possible exposure of that information more than a year after the reported incident doesn’t inspire confidence. It raises serious questions about communication, transparency, and how organizations respond when the people they serve may be at risk.

This situation also highlights a larger issue that extends beyond a single organization.

Data breaches have become so common that many people almost expect them. Banks, retailers, healthcare providers, schools, government agencies, nonprofit organizations, and organizations serving people with disabilities have all experienced cybersecurity incidents. While no organization can guarantee it will never become the next victim, every organization can control how it responds once an incident is discovered.

For organizations serving the disability community, communication is especially important. Many clients rely on regional centers for essential services and may not regularly follow cybersecurity news. Some depend on family members, caregivers, or advocates to help manage important correspondence. Delayed notifications reduce the amount of time people have to monitor financial accounts, review credit reports, change passwords, place fraud alerts, freeze their credit, or take other protective measures.

Whether you are directly affected by this incident or simply reading about it, this serves as another reminder to remain vigilant. Review your financial statements, monitor your credit reports, use strong and unique passwords, enable multi-factor authentication wherever possible, and be cautious of unexpected phone calls, emails, or text messages referencing this incident. Cybercriminals frequently use publicized breaches to launch convincing phishing campaigns against people who are already concerned about their personal information.

One thing I also noticed is that, as of this writing, this incident does not yet appear in Have I Been Pwned’s list of tracked breached websites. That doesn’t mean the incident didn’t happen or that the data won’t eventually appear there. Breach tracking services update on their own schedules, and not every incident results in a publicly searchable dataset. Still, it’s something I’ll be watching with interest.

I hope NLACRC continues to provide answers to the people it serves. Clients deserve to understand what happened, what information may have been affected, what additional protections have been put in place since the incident, and what guidance may become available as the investigation continues.

As someone who depends on NLACRC services, I don’t expect perfection. Cyberattacks can happen to any organization. What I do expect is timely communication, transparency, and clear answers when something this significant affects the people an organization exists to serve.

Until then, I encourage anyone who receives one of these letters to read it carefully, take advantage of any assistance being offered, monitor their accounts, consider placing a fraud alert or credit freeze if appropriate, and remain alert for signs of identity theft or fraud.

No one expects an organization to be perfect. There is no such thing anymore.

But transparency is the key.

Resources


Discover more from Jared's Technology podcast network

Subscribe to get the latest posts sent to your email.

One Comment

  1. crashmaster
    crashmaster July 22, 2026

    Hi jared.
    You are right to be furious.
    Sadly breaches like this happen all the time.
    Fact is not just breaches.
    I have had various things happen and so on in my organisation which in any normal trading things I’d just say “fuck you” and leave for another.
    The issue is we can’t there maybe only a few organisations in the industry and maybe a main one.
    Technically there is a monitering union on top of that but really when you know that there isn’t much competition, unless you really piss the government off if they even care you have the monopoly and can say fuck off to your users and they can’t do much about it.
    In normal life companies do this a lot.
    You leave, join another, they go bankrupt and you switch.
    But a disability organisation is not a power company!
    They know this.
    They also know you won’t leave because you can’t.
    So they can do what they want and you are helpless and if you complain well anything can happen.
    So you don’t.
    I have gotten critical in the past but again, its the only company I can lock with so I just let them do whatever, what choice do I have I am disabled after all, poor and helpless and they are normals.
    Its not like I can switch power plans.
    There are interesting things with funding I have heard in australia and different to this but the organisation has the power the members are not necesarily the guys in charge even if its user controled.
    I am also testing for a company I won’t name names.
    I wanted to give them something that was opensource to impliment and they assure they have seen it.
    Its a speech synth for a program I use.
    I have given all the information yet its never appeared.
    Currently there is a bug due to installation where on download of the installer certain actions are performed the user didn’t ask for and its been proven to be a bug.
    Those bugs are high priority, and yet we are up to rc1 for release and these are not fixed.
    Its just as well I am just a tester and not being payed but if even me an insider tester of this company is having issue at internal level what chance does an external user have?
    The only times when anything like this gets handled semi right is if the breach hits the news.
    Most of the time it doesn’t and or can be satisfied.
    There are many security breaches, misidentification of reccords, swapping of information all the time.
    People throw a stink like you are doing.
    Of course you do.
    You are a member of an organisation and you expect them to do right by you or hope so.
    However, even normals have a hard time and its all over the joint.
    The only thing different is they can move on.
    You can’t because its the only company and even if you did you may indirectly interact with that company.
    I have had issues where I get an appointment through to me and its a database error and it gets fixed.
    I once had an issue with a department I was working on.
    Again, no names but it manages benefits, and income for the disabled.
    And yes its a government entity.
    It is required for me when going away to report to this entity that I will be away fromx date to x date to make sure I fit the guidelines as there is a limit.
    Thats fine I guess.
    I needed to ring them at that point to do so as their systems online were well not that good.
    For the last 3 trips I would report, then get a message my benefit had been cut.
    I’d contact them and be told, it was a database error and my data was safe.
    And for a bit that was fine.
    Then one trip I put the wrong information in for when I left.
    I immediately called back and fixed the issue with assurances it would be updated.
    When I returned, yet again another letter but this time more serious.
    Again the threats and cuts.
    I called back expecting the same speech but no.
    This time my information didn’t exist in the database.
    I’d have to go through processes to well get back things to where they were.
    Luckilly I had my father close to me and he took over, threatening legal workings.
    Eventually a superviser listened to my recordings and realised I had tried my best.
    They assigned me a case manager and they were able to reset things.
    Still furious I contacted contacts in a user list for my organisation union and found out that there were system errors in the department which front desk staff were not told about.
    Shortly after that exchange the issues were fixed.
    When I login to report the information to the ai enhanced system its always been calculated correctly.
    I have not needed to interact with the department directly for some time and will make sure that if I do to write down my dates so if they fail again I will be able to handle things.
    Thankfully I haven’t needed to interact due to familly finances with any organisation or department on a major scale for a spell.
    No doubt I will again, but still.
    If I hadn’t had assistance from family at the time I’d be doing everything I was told to do in fear of getting things cut.
    They could tell me to kill a thousand people and I’d probably do that to keep being payed!
    This is the situation we disabled find ourselves in.
    Technically we are free but even though we can potentially work and live anywhere we want the only difference to our existance is that we are not in institutions but we are still with the same walls and bindings and we still have to do what they say or else.
    Its packaged differently and granted we have more freedom inside our cells but thats about it.
    What a lot of sightlings don’t get is we can’t say fuck off and go even if we wish.
    This unfortunately is life, and it is what it is.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.