Thousands of Labor Department employees’ sensitive personal and medical information was improperly shared to someone’s personal email account, according to an internal memo about the incident.
The Labor Department recently notified employees about an “internal incident” on July 22, in which an email containing a spreadsheet of personally identifiable information related to employees’ reasonable accommodations requests was sent to an “individual’s personal email address outside of the DOL domain.”
Following an initial investigation, the department “discovered that more than one email” containing PII or protected health information (PHI) was sent to the same personal email address outside of the DOL domain.
According to the Labor Department, the individual “had authorized access to the information in the performance of their DOL duties,” but did not have the authority to send the information to a personal email address.
According to a “talking points” memo obtained by Government Executive, the department’s Office of the Assistant Secretary for Administration and Management says the data leak discovered this summer impacted nearly 3,150 employees, all of whom submitted a reasonable accommodation request sometime over the past two-and-a-half years.
The talking-points memo states that the spreadsheet contained the personally identifiable information (PII) and protected health information (PHI) of employees who submitted reasonable accommodation requests between October 2023 and June 1, 2026.
The memo states that DOL “sent notification letters to all impacted individuals by mail,” and that the department “is reviewing and considering current and new measures that may be necessary to safeguard the information.”
“The Department is extremely concerned about the recent disclosure of personal information maintained on behalf of DOL employees. DOL will continue to engage in remediation activities to recover and destroy all the information involved in this incident,” the department wrote in its talking-points memo.
The Labor Department did not immediately respond to a request for comment.
Data impacted by the leak includes employees’ first and last names, duty location, work email address, job title, supervisor name and email address, pay grade and series. The spreadsheet also included information about each employees’ disabilities or medical conditions that were the basis of their reasonable accommodation requests.
Naomi Berry-Perez, director of the department’s Civil Rights Center, previously told employees that “no Social Security Numbers (SSNs), dates of birth (DOBs), more specific medical diagnoses” were included in the spreadsheet.
Union officials said they’re frustrated the department waited about a month after discovering the data leak to notify impacted employees. They say the department has also been unable to answer basic questions about the incident – including the position, title and affiliation of the individual who sent the data to their personal email address, or why the information was sent to a non-agency email more than once.
Brent Barron, president of the American Federation of Government Employees’ National Council of Field Labor Locals (NCFLL), said the Labor Department has been “dragging their feet” processing employees’ reasonable accommodation requests, and was slow to notify employees impacted by the data leak.
“We take pride in protecting the American workforce, and our own agency can’t protect its employees,” Barron said.
Labor Department employees recently told Government Executive that the department is facing a backlog of hundreds of RA requests. Several reported waiting months or, in some cases, a year or longer for the department to process their requests.
Faced with a backlog of reasonable accommodation requests, the department is looking to roll out artificial intelligence tools to triage the workload. Experts warned that processing confidential medical records through AI tools could create privacy issues.

