Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Data Privacy topic

No spam. Unsubscribe anytime.

Region 15: PowerSchool vendor breach exposed demographic fields; district says vendor responsible for security

AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Superintendent Smith told the Region 15 board that a national PowerSchool data‑hosting vendor breach exposed demographic fields for student records the vendor hosts, and that PowerSchool has notified schools, identified and mitigated the incident and reported data destruction.

Superintendent Smith told the Region 15 Board of Education on Jan. 3 that the district was notified by vendor PowerSchool of a national data breach affecting hosted student records. "Once they told us where to look, we found where the person would need access, and it took less than 5 seconds to pull, like, 1, 5 years worth of data," Smith said.

Smith explained that the data in question were hosted by the vendor under a district contract; while the district provides and controls the data, PowerSchool is contractually responsible for securing its systems. "This is not a Region 15 data breach. This wasn't our system...we host that data with them, their responsibility for the security of it," Smith said.

The superintendent said the fields accessed were largely demographic (contact and enrollment information) rather than medical records. He said PowerSchool informed the district about the affected fields on Jan. 17 and assured the district that it had identified the actor, mitigated access and destroyed the data copies. Smith said the vendor told districts it used discovery and destruction methods and would provide protections or remedies to impacted families.

Smith noted legacy records: Connecticut began using a student identification number after 2007; prior to that, some systems relied on Social Security numbers, so "there may be some data, not of any student that's active," in legacy fields. The district said it does not store Social Security numbers for active students after that date.

Why it matters: the breach involves personally identifiable student information held by a vendor; school administrators said they will hold the vendor accountable under contract and expect the company to provide remedies to affected families. The district said it has cyber‑insurance but expects vendor responsibility for this incident.

Ending: Administration said it will monitor PowerSchool’s notifications to families and will continue to press the vendor for remediation and assurances under the district contract.