WASHINGTON, D.C. (Bloomberg Law) — Parker Purifoy: The US Labor Department has told employees who requested reasonable accommodations at the agency that their personal information was improperly sent to an email account outside the DOL’s network.
The department learned of the leak July 22 through an internal incident report, Naomi Berry-Perez, director of the Civil Rights Center, wrote in an email to workers. A spreadsheet containing personal information such as workers’ names, work locations, email addresses, job titles, pay grade, and protected health information was sent to a personal email address, she said.
“The individual had authorized access to the information in the performance of their DOL duties. However, the individual did not have the authority to send the information to a personal email address,” Berry-Perez wrote in the letter reviewed by Bloomberg Law.
The Trump administration’s back-to-office push — along with a drastic reduction in staff at the Civil Rights Center — has led to a ballooning backlog of accommodations requests. The DOL told representatives from the workers’ union in June it had around 1,000 pending applications for accommodations, according to a person familiar with the conversations.
CRC leaders then said they planned to use artificial intelligence software to help triage requests but didn’t detail how, the person added.
The spreadsheet didn’t contain Social Security information, specific medical diagnoses, or workers’ financial information beyond their pay grade, according to the letter to workers.
But Berry-Perez said the leak could be broader than the single spreadsheet. Through investigating the incident report, the department discovered that more emails containing personal health information had been sent to the same email address.
The DOL said it was “currently assessing the scope and impact of these related incidents,” and was engaging in “remediation activities to recover and destroy” the leaked information.
Nora Ezzat Cozzillio, an attorney representing federal workers at Tully Rinckey PLLC, said the leak could open the DOL up to lawsuits under Health Insurance Portability and Accountability Act, which sets strict standards for managing, transmitting, and storing protected health information.
“Now that the medical records are out there and not protected they are more accessible to hackers and/or others who want that information,” Cozzillio said.
The administration has been pushing federal workers to return to the office since last year. The only workers who were exempted from the requirements were those with pre-existing accommodations due to a disability or health condition.
A DOL spokesperson didn’t respond to a request for comment.



