Ex-Lehighton employee sues district
A former Lehighton Area School District employee has filed a class-action lawsuit against the district after a sitting school board member published approximately 120,000 unredacted financial documents to a publicly accessible website — exposing the Social Security numbers of current and former employees, students and their families.
Leon William Brong filed the complaint July 27 in the Court of Common Pleas of Carbon County, alleging “negligence, negligence per se and breach of implied contract.”
The lawsuit, which seeks a jury trial, names the Lehighton Area School District as the sole defendant.
Documents published on unsecure site
The documents were published on or around May 13, 2026, on a website operating under the domain lehightongovt.org by David F. Bradley Sr., a current member of the Lehighton Area School District Board of Directors. The complaint describes the site as “an openly searchable, publicly indexed site, accessible to anyone, carrying no password protection, login requirement, or other access restrictions.”
The browser bar visible to any visitor, the complaint states, displayed the notation “Not Secure,” indicating the site lacked even basic encryption protocols.
Among the published records were payroll-adjacent financial documents — including a Voluntary Deduction History Report — that displayed “students’ and employees’ complete legal names alongside their complete nine-digit Social Security numbers, with no masking, truncation, or redaction of any kind,” according to the complaint. Benefits-related financial records containing personal identifiers for employees, their spouses and dependent children also appeared across dozens of uploaded PDFs.
Years of legal battles over records
The disclosure, the complaint alleges, was the culmination of years of legal battles rooted in a Right-to-Know Law request Bradley submitted in April 2022 seeking six years of the district’s financial records.
The district initially denied the request, citing that it was insufficiently specific, duplicative of a prior request and that some records were already publicly available online.
Bradley appealed to the Pennsylvania Office of Open Records, which ordered the district to make all responsive records available without redactions. The district did not immediately comply — and did not appeal the ruling.
“The district also had thirty days to appeal the OOR’s Final Determination to the Court of Common Pleas,” the complaint states, noting that a timely appeal would have placed the disclosure question before a court with full authority to consider privacy protections — including independent federal and state protections applicable to Social Security numbers.
The district did not appeal. As of mid-September 2022, the OOR’s order had become final.
Seventeen months of noncompliance
What followed, the complaint alleges, was seventeen months of noncompliance. The district’s superintendent met with Bradley and told him he could come to “spot-check” records, but no date was set and no records were prepared. Former Business Administrator Edward Rarick, the official responsible for the district’s financial records who was aware of the OOR’s order, “testified at trial that he did not believe it was ‘his responsibility’ to ensure compliance,” the complaint states. “No one within the District’s administration, apparently, assigned that responsibility to anyone, because no one acted.”
Bradley eventually filed a complaint in mandamus in October 2022, seeking a court order requiring the district to allow inspection of all granted records. A subsequent motion requested civil penalties and attorneys’ fees.
On Dec. 10, 2024, Judge Joseph J. Matika entered an Order for Sanctions, finding that the district had acted in bad faith, specifically citing its redaction of records on Jan. 8, 2024, in violation of the OOR’s order. The court imposed a $500 civil penalty, ordered the district to pay Bradley’s reasonable attorneys’ fees and directed reimbursement of $731.25 in photocopying costs Bradley had been improperly charged.
The sanctions order acknowledged that the records contain personal information that is “otherwise exempt” from disclosure under the Right-to-Know Law — but found that the district’s failure to assert and prove those exemptions at the OOR level, and its failure to appeal the OOR’s adverse ruling, had stripped it of the legal authority to redact that information after the fact.
As a consequence, the complaint states, “the District gave Mr. Bradley extensive unredacted records containing Plaintiff’s and Class Members’ Social Security numbers and other sensitive information.”
District failed to invoke privacy protections
The complaint argues the district was obligated under Pennsylvania law to protect such information from the outset. The RTKL, the complaint notes, contains privacy exemptions that the district could have invoked, including a provision stating that a record containing “all or part of a person’s Social Security number, driver’s license number, personal financial information, home, cellular or personal telephone numbers, personal email addresses, employee number or other confidential personal identification number” is “exempt from access by a requester under this act.”
“The District did not invoke any of the Right-to-Know Law’s privacy exemptions,” the complaint states, adding that it “did not identify specific records containing Social Security numbers or other sensitive data” and “did not ask the OOR to enter a partial order requiring redaction of protected fields before disclosure.”
Brong’s attorney describes lasting harm
Brong, the named plaintiff, is described in the complaint as a former district employee who “has never knowingly transmitted unencrypted sensitive PII over the Internet or any other unsecured source.” As a result of the breach, he spent time verifying its legitimacy, changing passwords and reviewing credit activity.
“This time has been lost forever and cannot be recaptured,” the complaint states.
“Once PII is exposed, there is virtually no way to ensure that the exposed information has been fully recovered or contained against future misuse,” the complaint states. “Plaintiff Brong will need to maintain these heightened measures for years.”
Thousands could be included in class
The complaint proposes a class defined as all persons whose personally identifiable information was compromised in connection with the data breach disclosed by the district on or around May 14, 2026. Excluded from the class are the district’s officers and directors, affiliates, legal representatives, attorneys, successors, heirs and assigns, as well as members of the judiciary to whom the case is assigned, their families and staff.
The complaint estimates the class numbers in the thousands, comprising current and former district employees, retirees, students and their families.
“Plaintiff and Class Members provided their PII to the District with the reasonable expectation and mutual understanding that the District would comply with its obligations to keep such information confidential and secure from unauthorized access,” the complaint states.
Among the remedies sought are at least ten years of credit monitoring services for all class members, actual and compensatory damages, punitive damages, attorneys’ fees, and injunctive relief requiring the district to strengthen its data security systems and RTK response procedures and submit to future annual audits.
Brong is represented by Benjamin F. Johns and Samantha E. Holbrook of Shub Johns & Holbrook LLP in Conshohocken and Matthew D. Schelkopf of Sauder Schelkopf in Berwyn.