LACMA Data Breach Exposes Sensitive Medical and Financial Data

Published
August 26, 2026
Updated
August 26, 2026
LACMA Data Breach Exposes Sensitive Medical and Financial Data
LACMA
Affected by the data breach? You may be entitled to compensation. Submit a claim today.

LACMA, the Los Angeles County Museum of Art, has disclosed a data breach that occurred in July 2025 and exposed sensitive personal and medical information.

An unauthorized third party gained access to a portion of Lacma's computer network from July 7 to 11, 2025.

After detecting suspicious activity on its network, Lacma began working with third-party cybersecurity experts to investigate and address the intrusion. By August 2025, the investigation confirmed that unauthorized access had occurred during that four-day window in July.

Lacma identified the specific files involved in the breach and engaged a separate data-review firm to determine what personal information those files contained. The museum received initial results from that review in late February 2026. In the months that followed, Lacma worked to obtain accurate contact information for affected individuals before sending out notification letters.

The breach exposed a wide range of sensitive data. Personally identifiable information exposed included full names, dates of birth, Social Security numbers, driver's license or government-issued identification numbers, financial account numbers and payment card information.

Protected health information was also compromised, including diagnoses, health-insurance information, and medical information such as provider names, medical treatment or treatment locations and treatment dates.

Lacma began notifying affected individuals on Aug. 24, 2026. The breach was reported to the California Attorney General, and the museum posted a notice about the incident on its website.

LACMA's response to the breach

LACMA is offering a complimentary one-year membership to Financial Shield, an identity-theft and fraud protection service. Affected individuals can enroll by visiting the Financial Shield enrollment page and entering the unique activation code included in their notification letter. Enrollment must be completed by Nov. 22, 2026.

The notification also states that Experian Identity Works is available as an alternative to the online enrollment through Financial Shield. Individuals who prefer this option or who have questions about the enrollment process can contact Experian directly using the phone number and activation code provided in their notification letter.

SUBMIT YOUR CLAIM TO THE LAW FIRM HANDLING THIS INVESTIGATION

Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info
  • Affected information types not yet disclosed

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Affected Entity
LACMA
Consumers Notification date
Date of Breach
July 7, 2025
Breach Discovered Date
July 11, 2025
Total People Affected
Information Types Exposed
  • Social Security number
  • date of birth
  • diagnosis
  • driver’s license or government-issued identification number
  • full name
  • health-insurance information
  • limited financial account numbers
  • limited medical information such as provider name
  • limited
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image