Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Data Breach topic

No spam. Unsubscribe anytime.

After PowerSchool data breach, district to send notification letter and coordinates with vendor counsel

AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Bedford administrators said on Jan. 13 they have been advised by the vendor's cyber‑insurance counsel to send a bridge letter to families and staff and to direct claimants to PowerSchool resources. Counsel and a vendor‑contracted firm will lead breach response; the district said it will not assume vendor liabi

Bedford School District administrators told the board on Jan. 13 that they are coordinating a response after a widely reported PowerSchool data breach that affects many New Hampshire school districts.

Superintendent Mike Fournier said the district was directed by PowerSchool's cyber‑insurance provider (a firm referred to in the meeting as Beasley) to engage counsel and to send a bridge notice to staff and families explaining what immediate steps they can take to protect themselves. Fournier said the vendor will be the primary party handling the breach response but that the district must assist by communicating to families and employees and by pointing them to vendor resources where appropriate.

Administrators said the district will issue a bridge letter to parents and staff advising them how to protect personal information and where to seek additional assistance; the letter was expected to be sent the following day. Counsel assigned through the vendor's insurer will be the district's contact for legal questions tied to the breach. Fournier and trustees stressed that the breach originated with the third‑party vendor and is not the result of a district system compromise; nevertheless, because the district uses the product to manage student and employee information, families and staff need practical guidance and protections.

The board discussed categories of exposed data and legal implications. Fournier noted the distinction between directory information (name, grade, address) and personally identifiable information such as Social Security numbers, which carry a different level of legal risk. Administrators said they are working with counsel and PowerSchool to determine exactly which categories of information were affected and whether affected individuals must be notified under state or federal rules.

No vote was required; administrators said they will continue to update the board and that PowerSchool and counsel would take point on the technical remediation and notification process. The district recommended that parents and staff consider standard protections (credit monitoring, fraud alerts) and that the district will forward vendor guidance once it is available.