Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Data Privacy topic

No spam. Unsubscribe anytime.

OCTO says three recent data incidents were contained; cautions on prompts and FOIA applicability

Committee on Public Works and Operations · February 27, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Stephen Miller told the committee OCTO recorded three notable data incidents in the last three years, including a DCHR email exposure and a MoveIt file-transfer matter; he said Copilot Chat runs in a secure government tenant, prompts are auditable, and records are available through normal discovery.

Stephen Miller, OCTO director, told the committee that over the last three years OCTO has investigated three notable incidents involving improper data handling. Miller characterized the incidents as limited in scope: an email exposure at DCHR that was promptly contained, account‑and‑password sharing incidents, and an older MoveIt-related exposure in a health-related office that led to migration to enterprise secure file-transfer tools.

"We were lucky to not have many incidents, but we have had 3," Miller said, adding that two of the incidents involved personally identifiable information and that OCTO's security operations center tracks incidents and coordinates remediation with agency leadership and ORM. He said OCTO would notify the city administrator for agencies with repeated incidents and would work with agency CIOs on remediation plans.

On record-keeping and FOIA, Miller said Copilot Chat operates in a secure government tenant and that prompts and chat content are auditable and retained in a manner similar to other enterprise communications (e.g., Teams or Outlook) and thus can be available through discovery. He emphasized that OCTO does not host models in its own data centers and relies on governed enterprise tenants from vendors to ensure compliance with standards such as FedRAMP and NIST-aligned controls.

The committee asked OCTO for a breakdown of incidents year over year and for a copy of the AI handbook, and Miller agreed to provide those materials to staff.