Maximus, a government services company, discovered a security incident on April 27, 2026, involving the Nebraska Provider Data Management System (PDMS), which it operates for the Nebraska Department of Health and Human Services. The company notified the Nebraska Department of Health and Human Services the same day. By June 16, 2026, Maximus determined that personal information may have been impacted, and consumers were notified by July 28, 2026. The exposed data types include first and last names, dates of birth, and Social Security numbers. The exact number of affected individuals remains unclear, with secondary reporting referencing varying figures that are not independently verified by official filings. The breach was reported to the Massachusetts Attorney General on July 28, 2026. Active litigation includes multiple federal lawsuits filed against Maximus entities in various districts. While a lawsuit investigation page exists, the provided sources do not confirm an MDL status for this incident. Details regarding the full scope of affected data types and individuals continue to emerge.