Nursa, a healthcare staffing platform, experienced a data breach in two separate incidents on February 27, 2026, and March 18, 2026. An unauthorized third party accessed user profiles on its web application. Nursa confirmed the unauthorized access and began notifying affected consumers starting May 13, 2026.
The breach exposed names, Social Security Numbers, dates of birth, addresses, government IDs, medical information, and financial information for 13,168 Washington residents. The total number of affected individuals across the United States has not yet been publicly disclosed. It is not classified as a HIPAA Business Associate breach as the breach occurred on Nursa's own web application.
Information regarding the breach and its impact can emerge over time, and notification efforts may be ongoing.