Last Updated: September 2, 2026 Reading Time: 8 min

Roughly 3,150 Department of Labor employees received letters in late August telling them that a spreadsheet of their reasonable-accommodation records, including the category of their disability, had been emailed by a DOL employee to an outside personal account. The department discovered it on July 22 and took about a month to notify anyone. This post covers what was exposed, what the law gives the affected employees, and the two clocks that started the day those letters arrived. If you work anywhere else in government, read it as the playbook for when it happens at your agency.

What Happened, in Order

Date Event
October 2023 to June 1, 2026 Window of reasonable-accommodation requests whose records were in the spreadsheet
July 22, 2026 DOL discovers that an employee emailed the spreadsheet to an outside personal account; more than one such email went to the same address
Late August 2026 Notification letters mailed to about 3,150 affected employees, signed by the director of DOL's Civil Rights Center
August 28 to 29, 2026 GovExec publishes two reports, the second citing an internal DOL talking-points memo
Now Each recipient's 45-day EEO clock and two-year Privacy Act clock are running from the date their letter arrived

DOL's statement, as reported, is that the sender had authorized access to the records for their job but no authority to send them outside the department, and that the agency is "assessing the scope and impact" and working to "recover and destroy" the data. No credit monitoring or identity-restoration offer had been confirmed as of this writing. AFGE's National Council of Field Labor Locals president told GovExec that about 80 employees contacted the union within an hour of the letters landing.

These facts come from GovExec's reporting on the DOL memo and notification letter. FedTools has not seen a DOL press release, inspector general report, or congressional letter on the incident; where something is unconfirmed, this post says so.

What the DOL Accommodation Data Leak Exposed, and What It Did Not

In the spreadsheet: name, duty station, work email address, job title, supervisor's name and email, pay grade and series, and the category of the employee's disability or functional limitation (the reported categories include mental health, chronic condition, pregnancy, vision, hearing, and mobility).

Not in the spreadsheet, per DOL: Social Security numbers, dates of birth, specific medical diagnoses, medical documentation, and financial information.

That mix matters for remedies. Without SSNs, the identity-theft risk is low and the breach-notification playbook built for consumer data mostly does not apply. With disability categories tied to names and supervisors, the confidentiality violation is direct, and the legal exposure runs through employment law, not just data-security policy.

How Big Is 3,150? A FedTools Comparison

DOL's civilian workforce stood at roughly 11,000 as of May 2026, down from about 16,600 in 2010. The 3,150 employees whose records were exposed are a cumulative count of everyone who filed an accommodation request over about two and a half years, so the comparison is approximate, but it works out to about 29% of the current headcount. Government-wide, EEOC's workforce reports put the share of federal employees who self-identify as having a disability at roughly 9.4% to 10.5%.

FedTools analysis, September 2026, of GovExec-reported incident data against USAFacts and OPM headcount figures and EEOC FY2018 to FY2021 workforce reports. No clean government-wide count of employees with an approved accommodation exists, which is itself part of the problem: agencies track accommodation procedures, not the population of people whose records they hold.

Your Remedies, Statute by Statute

Authority What it gives you Deadline Where
Privacy Act, 5 U.S.C. 552a(g)(1)(D) and (g)(4) Civil suit for a willful or intentional unauthorized disclosure: actual damages, no less than $1,000, plus attorney's fees and costs if you substantially prevail. No emotional-distress damages (FAA v. Cooper, 2012) Two years from when you knew or should have known (552a(g)(5)) U.S. District Court
Privacy Act criminal provision, 552a(i)(1) Misdemeanor for the employee who willfully disclosed; fine up to $5,000 None for you; DOJ referral Report through the agency inspector general
Privacy Act access and accounting, 552a(d) A copy of your own accommodation file and an accounting of every disclosure of it None; request now DOL Civil Rights Center or Privacy Act office
Rehabilitation Act confidentiality, 29 CFR 1630.14(c), through the EEO process An EEO complaint that the disclosure itself violated the mandatory confidentiality of medical information 45 calendar days from notice (29 CFR 1614.105) Agency EEO counselor
OMB M-17-12 breach policy A documented risk-of-harm assessment and notification; credit monitoring or other services at agency discretion Agency-driven DOL Chief Privacy Officer
Whistleblower Protection Act, 5 U.S.C. 2302(b)(8) Protection from retaliation for reporting the mishandling as a violation of law or gross mismanagement, for any DOL employee, not just the 3,150 Report promptly Office of Special Counsel or agency IG
FTC identity-theft process A recovery plan if misuse occurs; low relevance without SSN exposure On suspicion of misuse identitytheft.gov

Two rows in that table need more explanation.

The Privacy Act ceiling is real. In FAA v. Cooper, the Supreme Court held 5 to 3 that "actual damages" under the Privacy Act excludes mental and emotional distress. That case involved a federal agency disclosing an employee's confidential medical information, a near-identical fact pattern. An affected DOL employee who cannot show out-of-pocket loss is looking at the $1,000 statutory floor and fees, and only if a court finds the disclosure willful or intentional rather than merely negligent.

The EEO track has no such ceiling but a much shorter fuse. Medical information about an employee's disability must be kept in separate, confidential files under 29 CFR 1630.14(c). A spreadsheet of accommodation categories emailed to a personal account is outside every exception the regulation lists. That is a confidentiality violation tied to disability status, which is what makes it an EEO matter. The 45-day counselor-contact rule applies, and it does not pause while the agency investigates.

Why Credit Monitoring Is Not Guaranteed

State consumer breach laws often require free monitoring when personal data leaks. Federal agencies operate under OMB Memorandum M-17-12 instead. It requires the agency's breach response team to run a risk-of-harm assessment, weighing embarrassment, unfairness, and financial or identity harm, and then decide whether and how to notify and what services, if any, to offer.

Because no SSNs, birth dates, or account numbers were exposed, DOL can defensibly conclude that identity-monitoring services are not warranted. What M-17-12 does require is the notice itself, which DOL sent, and a documented assessment. Affected employees can ask for that assessment through a Privacy Act request and can argue, in writing, that the reputational and workplace harm of a disclosed disability category deserves a response even if the financial risk is low.

Reporting It Is Protected, Even If You Were Not Affected

The Whistleblower Protection Act covers any DOL employee, including IT staff, union representatives, and coworkers, who discloses information they reasonably believe shows a violation of law or gross mismanagement. Repeated unauthorized transmission of protected medical information fits that description. Reports to the agency inspector general or the Office of Special Counsel are confidential absent consent, and retaliation for making one is itself a prohibited personnel practice.

The Checklist, in Order

  1. Save the notification letter and write down the date you received it. That date anchors both clocks.
  2. File a Privacy Act access request under 552a(d) for your accommodation file and an accounting of disclosures. Do this whether or not you plan to sue; it builds the record.
  3. Contact an EEO counselor within 45 calendar days if you want to preserve a confidentiality claim. Waiting to see what DOL does forfeits the option.
  4. Ask your union about a grievance. AFGE NCFLL is already engaged on this incident, and the grievance track can move faster than EEO for some outcomes.
  5. Request DOL's M-17-12 risk assessment and state, in writing, what services you believe it supports.
  6. Place a free credit freeze. It costs nothing and takes fifteen minutes. It is a precaution, not an admission that SSNs were involved.
  7. Track the two-year Privacy Act window even if you do not intend to file. Evidence and memory both fade.

If This Is the Last Straw

Some of the people on that spreadsheet were already weighing whether to stay. A leak of your disability category to a personal inbox is a reasonable reason to run the numbers. The FERS Retirement Calculator shows what an immediate, deferred, or postponed annuity looks like from your current high-3 and service time, so the decision to stay or go is made on figures rather than anger. Run your retirement numbers →

Frequently Asked Questions

What data did the Labor Department leak, and were Social Security numbers exposed?

No Social Security numbers. According to GovExec's reporting on the internal memo, the spreadsheet emailed to an outside personal account held names, duty stations, work emails, job titles, pay grades and series, supervisor names, and the category of each employee's disability or functional limitation. Dates of birth, specific diagnoses, medical documents, and financial data were not included.

Can affected employees sue under the Privacy Act, and what can they win?

Yes, if the disclosure was willful or intentional. Under 5 U.S.C. 552a(g)(4) the remedy is actual damages with a $1,000 floor plus attorney's fees. Under FAA v. Cooper (2012), a case about a federal agency disclosing an employee's medical information, emotional-distress damages are not recoverable. The suit must be filed within two years of when you knew or should have known.

Is a leak of accommodation records an EEO issue or only a data-security problem?

Both. Rehabilitation Act regulations at 29 CFR 1630.14(c) require disability-related medical information to be kept in separate confidential files with narrow exceptions, and emailing it to a personal account is not one of them. That makes the leak itself a potential EEO confidentiality claim with the usual 45-calendar-day clock to contact an EEO counselor under 29 CFR 1614.105.

Does the agency's ongoing investigation pause my deadlines?

No. The 45-day EEO counselor clock runs from the day you received your notification letter, and the two-year Privacy Act limitations period runs from when you knew or should have known of the disclosure. Neither waits for the agency to finish assessing the incident.

Is DOL required to offer credit monitoring to the affected employees?

Not automatically. OMB Memorandum M-17-12 requires a risk-of-harm assessment and leaves services such as credit monitoring to the agency's discretion. Because no SSNs or financial data were exposed, DOL may conclude monitoring is not warranted. You can ask, in writing, for the risk assessment and for the services it supports.

What happened to the employee who sent the data?

DOL has said the sender had authorized access for their duties but not authority to send the data externally, and that more than one email went to the same personal account. The sender's identity and any discipline had not been disclosed as of September 2, 2026. The Privacy Act's criminal provision at 5 U.S.C. 552a(i)(1) makes willful unauthorized disclosure a misdemeanor, referred by the Justice Department.

How is this different from the 2015 OPM breach?

Scale and data type. The 2015 breach exposed background-investigation records including SSNs for 22.1 million people and came with government-funded identity protection through September 30, 2026. The DOL incident affects about 3,150 people and did not expose SSNs, so it does not trigger that kind of remedy. The confidentiality and Privacy Act claims are stronger here because the data was medical in nature.

I am one of the 3,150. What should I do this week?

Save the notification letter and note the date you received it. File a Privacy Act access request with DOL for your accommodation file and an accounting of disclosures. Contact an EEO counselor within 45 days if you want to preserve a confidentiality claim. Ask your union about a grievance. Place a free credit freeze as a precaution even though SSNs were not exposed.

Sources: GovExec reporting, August 28 and 29, 2026 (internal DOL memo and notification letter); 5 U.S.C. § 552a (Privacy Act); FAA v. Cooper, 566 U.S. 284 (2012); 29 CFR § 1630.14; 29 CFR § 1614.105; OMB Memorandum M-17-12 (2017); 5 U.S.C. § 2302(b)(8); USAFacts/OPM DOL headcount (May 2026); EEOC Annual Reports on the Federal Workforce (FY2018 to FY2021).