Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the School Data Breach topic
No spam. Unsubscribe anytime.
Williamson County Schools to offer identity-protection after data breach affecting about 5,200 students
Summary
Director of schools Rebecca Scharber told commissioners the district identified roughly 5,200 students affected by a testing-data breach, will self-report the FERPA violation to the U.S. Department of Education, and is negotiating an identity-theft protection contract for families for under $100,000.
Get email alerts on the School Data Breach topic
No spam. Unsubscribe anytime.
Williamson County Director of Schools Dr. Rebecca Scharber told the county commission that the school system found student testing and identifying information on a website created by an assessment specialist and that the district has identified about 5,200 affected students.
Dr. Scharber said the assessment specialist, Chris Nugent, had created the site for graduate research and that the information appears to have been inadvertently uploaded from testing media such as discs. “We will be reporting to the U.S. Department of Education that violation,” she said, referring to the Family Educational Rights and Privacy Act (FERPA). She explained that the district must notify the department and describe the scope of the violation.
The district has been assembling a call list, mailing letters and negotiating a contract with a private identity-theft protection vendor to provide services to affected families. Dr. Scharber told commissioners the contract under negotiation “will be under $100,000,” and that the vendor would provide advocates and, when appropriate, assistance with credit reporting for families with children of various ages.
Scharber said the district did not immediately know which students were impacted until it obtained a list from the website operator last Thursday and then used internal records to match names and addresses. She said roughly 5,200 names were on the list and the district has been working to assemble contact information for mailing and outbound calls.
Commissioners pressed staff on how the breach occurred and whether state procedures for handling testing media need to change. Dr. Scharber said much testing data historically came on discs and that, until recently, Tennessee required social security numbers be used as student identifiers for multiple state systems. She said the district has already begun using state-provided PIN numbers for newly enrolled students and will press state officials to expand that approach to replace Social Security numbers more broadly.
On potential sanctions, Scharber said the penalty for a FERPA violation can include loss of federal funds but noted she is not aware of a district losing funds after reporting such a violation. When asked about the financial exposure, she said federal special-education funding accounts for the largest share of potential risk and estimated — based on the district’s current mix of federal funding — approximately $8,000,000 in federal special-education revenues could be affected if a sanction were imposed.
Families will receive a letter that explains what happened, names the company providing protection services, gives a phone number and PIN to enroll, and provides a district contact (communications director Birdsong) for help. The district’s attorney and purchasing and finance staff have reviewed the vendor contract, Scharber said.
Dr. Scharber and IT staff (Phil Fulmer) told the commission they are reviewing logging and access procedures, changing where testing media are routed, and tightening policies governing off-site usage of student information. She said the assessment specialist resigned; district leaders said disciplinary or dismissal procedures would have been pursued had he not resigned.
The commission asked the director to return with follow-up information as the vendor contract is finalized and to report on steps taken to reduce the risk that similar disclosures could recur.

