Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Data Privacy topic
No spam. Unsubscribe anytime.
Longmeadow Public Schools discloses PowerSchool data breach; district to offer credit monitoring
Summary
Superintendent told the School Committee a PowerSchool data export included personally identifiable fields for current staff and students and social security numbers for some former students; the district posted details and is arranging credit monitoring through PowerSchool while attorneys and IT continue the investigation.
Get email alerts on the Data Privacy topic
No spam. Unsubscribe anytime.
Longmeadow Public Schools announced at its Jan. 14 School Committee meeting that a data breach affecting the vendor PowerSchool copied and exported staff and student records, and that the district will work to offer credit monitoring to affected former students.
The superintendent told the committee the district posted a detailed list of the data fields copied from PowerSchool on the district website, notified staff and families, and is working with attorneys and its IT team to press PowerSchool for responsive remediation, including credit monitoring for those affected.
The disclosure matters because the exported fields included names, addresses, dates of birth and other personally identifiable information; the superintendent said a subset of former students who graduated or separated between 2005 and 2009 had social security numbers included in the export. The district said it will make a targeted outreach to those former students and expects to make credit-monitoring services available through PowerSchool.
Superintendent (unnamed in the meeting) said the district’s IT staff conducted forensic analysis to identify which fields were exported and assembled an FAQ and communications packet for families. "For the most part, it was data that did not include social security numbers, but ... there were some students who had either separated from us or graduated in the years between 2005, 2009 that in fact had social security numbers copied and exported as a result of the PowerSchool data breach," the superintendent said.
Committee members asked about privacy protections for other tools the district uses. School Committee member Mikaela asked whether Panorama (a student-data platform discussed later in the meeting) contained social security numbers. The superintendent answered that Panorama is siloed from the affected system and was not hit in the breach; he also said the district participates in a data-privacy consortium and reviews vendor controls before adoption.
The district said it has been on webinars and calls with PowerSchool and that its attorneys have escalated requests for remediation. The superintendent said further cybersecurity reviews are planned.
The committee did not take formal action on the breach at the Jan. 14 meeting; members asked to be kept informed and the superintendent invited committee questions for the IT team as the investigation continues.
Community members who want details are directed to the district landing page with the PowerSchool Data Breach updates, the superintendent said, which includes the vendor’s communications, a PowerSchool FAQ, and the district’s notices to families and staff.

