# The Art of Losing Data: LACMA's Year-Old Breach Left Employees Exposed to Identity Fraud


The Los Angeles County Museum of Art spent 2024 curating world-class exhibitions. Meanwhile, someone was quietly walking out with something far more valuable than artwork: the social security numbers and medical records of the people who work there.


LACMA confirmed a data breach that occurred last year exposed sensitive employee information — SSNs, medical data, the combination that identity thieves specifically hunt for because it enables both financial fraud and insurance fraud simultaneously. The disclosure came well after the fact, which is itself a story.


## Why SSNs and Medical Data Together Are a Different Category of Problem


Not all breaches are created equal. A leaked email address is annoying. A leaked credit card number gets you a replacement card. A leaked social security number combined with medical data is a different beast entirely.


The SSN is your permanent government-issued identifier — you can't change it the way you change a password. Pair that with medical records and an attacker has everything needed to file fraudulent insurance claims, obtain prescription drugs fraudulently, or engage in medical identity theft that can corrupt a victim's actual health records. Imagine showing up to an emergency room and having your chart reflect someone else's allergies or blood type.


This isn't speculative. The Identity Theft Resource Center has documented cases where victims spent years untangling corrupted medical records after a breach of this type. The financial damage is compounded by a health risk that doesn't go away with a credit freeze.


## Cultural Institutions: The Soft Underbelly of the Nonprofit Sector


LACMA isn't a hospital or a bank. It's a museum. And that's precisely why this breach deserves attention beyond the obvious victim count.


Cultural institutions — museums, symphonies, universities, nonprofits — sit in a uniquely dangerous position in the data ecosystem. They collect and retain sensitive employee HR data (including SSNs for payroll and benefits administration) and medical information (for health insurance enrollment, disability accommodations, leave management) while operating on nonprofit budgets that rarely prioritize information security infrastructure.


A regional bank has regulatory pressure and compliance mandates pushing it toward security investment. A museum has a board that's focused on acquisitions and donor cultivation. The CISO role, if it exists at all, is often a part-time responsibility folded into an IT director's job description.


This isn't unique to LACMA. The breach fits a pattern visible across the nonprofit and cultural sector: organizations holding substantial HR data, governed by HR compliance requirements that generate that data, but without the security posture to protect it. The University of California system, various hospital networks, and now a major art museum — the thread connecting them isn't sector but rather the mismatch between data sensitivity and security investment.


## The Disclosure Timeline Problem


"Last year" is doing a lot of work in this story. Data breach notification laws in California — and LACMA operates under California law — require organizations to notify affected individuals "in the most expedient time possible" following discovery of a breach. The state doesn't specify an exact window but the expectation is weeks, not months.


When a breach from last year is being reported on now, one of several things happened: the breach was discovered late, notification was delayed, or the public-facing disclosure lagged behind individual notifications. Any of those scenarios raises questions.


Late discovery typically means the attacker had extended access — dwell time is one of the most consequential variables in breach severity. The longer an attacker sits in a network, the more they can exfiltrate, the harder attribution becomes, and the harder it is to fully scope what was taken.


## What Employees Should Do Right Now


If you received a breach notification from LACMA, the steps aren't complicated but they need to happen immediately:


  • Freeze your credit at all three bureaus (Equifax, Experian, TransUnion) plus NCTUE and Innovis. This costs nothing under federal law.
  • Set up IRS Identity Protection PINs — a six-digit PIN that prevents anyone else from filing a tax return using your SSN.
  • Request your medical records from your health insurer to check for services you didn't receive.
  • Monitor your Explanation of Benefits statements monthly going forward.
  • Consider enrolling in the identity theft protection service LACMA offers (typically included in breach notification letters) — and read the fine print on what it actually covers.

  • The IRS PIN is the step most people skip. It's also the one that would have prevented significant harm in the 2015 IRS "Get Transcript" breach, which involved approximately 700,000 taxpayers. Don't skip it.


    ---


    ## HackWire Analysis


    The LACMA breach lands in a moment when we should be asking harder questions about who is responsible for securing the HR data of nonprofit employees.


    Here's what's missing from most coverage of incidents like this: the breach didn't happen because someone at LACMA made an obviously bad decision. It happened because the entire nonprofit sector operates under a structural security deficit that no one has seriously addressed. When federal and state governments mandate that organizations collect SSNs for tax purposes, maintain medical information for benefits compliance, and retain that data for years — but impose those requirements without corresponding security mandates or funding — you get exactly this outcome, repeatedly.


    The comparison that keeps coming up in the security community is healthcare: HIPAA created real compliance pressure and drove meaningful (if imperfect) security investment in clinical settings. The HR data of the country's museum workers, nonprofit employees, and arts professionals is comparably sensitive — SSNs plus medical data — but it exists in a regulatory gray zone that creates no similar pressure.


    What this breach signals to defenders at similar organizations: your exposure isn't primarily from sophisticated nation-state actors or ransomware groups targeting you specifically. It's from opportunistic attackers probing for organizations that haven't patched their HR systems, haven't implemented MFA on email, and haven't segmented the network in a way that limits what an attacker finds when they get in. Basic hygiene — the kind that doesn't require a large security budget — would have made this significantly harder.


    The cultural sector needs a HIPAA equivalent for employee data. Until it exists, museums and nonprofits should treat their HR systems with the same paranoia they'd apply to their most valuable artifacts. Probably more.


    — HackWire Editorial


    ---


    *Healthcare providers and organizations handling patient or employee medical data should review their security posture — for patient-facing health information resources, visit [VitaGuia](https://vitaguia.com) or [Lake Nona Medical Services](https://nonamedicalservices.com).*


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)