ResourcesTexas Breach Tracker › Travis County Health and Human Services
Municipal Exfil Remediated

Travis County Health and Human Services
Breach Analysis

Travis County Health and Human Services disclosed a data exfiltration incident in August 2024, affecting 37,000 Medicaid and benefits recipients. Sensitive PHI and benefits data was accessed via a compromised contractor credential.

Incident Date
2024-08-19
Records Exposed
37,000
Attack Type
Exfil
Threat Actor
Unconfirmed

How they got in

Contractor employee credential compromised via phishing. Contractor had broader-than-necessary access to benefits management system. Threat actor exfiltrated Medicaid and benefits eligibility records over a 72-hour window before detection.

Sentinel / Fortress / Command coverage

Sentinel Contractor access from anomalous IP/location triggers MFA step-up and SOC alert within minutes
Fortress Contractor access scoped to minimum required records — bulk export attempt denied by DLP rule
Command Annual contractor access review identifies over-privileged accounts; access trimmed to job function in prior cycle

Sentinel ($89/ep/mo) — 24/7 SOC + SIEM. Fortress ($109/ep/mo) — Sentinel + EDR management + vulnerability management. Command ($129/ep/mo) — Fortress + vCISO + compliance mapping + IR plan. See full tier comparison →

Regulatory exposure

Regime Standard / Citation Gap Identified
HIPAA 45 CFR §164.308(b) Business associate agreement — contractor lacked documented BAA with appropriate security requirements
TDPA Tex. B&C Code §521.053 37,000 TX Medicaid recipients required breach notification

5-point hardening list

CoreRecon cites verifiable public sources only. No speculation on unverified attribution is published. Threat actor attribution appears only where publicly confirmed by law enforcement or the organization.

Is your organization hardened against this attack vector?

Free $2,500 security posture assessment for Texas organizations. We map your gaps against the same attack vectors used in this incident. No contract, no commitment.