CONSUMER PROTECTION RESOURCES
DISA Global Solutions Background Check Errors
Home / Resources / Background Check Companies / DISA Global Solutions, Inc.
Resources
DISA Global Solutions Background Check Errors
If a DISA Global Solutions report or drug-screen result is standing between you and a job, an inaccurate result is not something you have to accept. DISA is a consumer reporting agency under the federal Fair Credit Reporting Act (FCRA), so you have the right to see what it reports about you and to make it correct mistakes. DISA files are unusual in one important way: a bad outcome can come out of three completely separate systems, each with its own decision-maker and its own deadline, and choosing the wrong door can quietly burn a right you cannot get back. You can learn more about your rights on our Employment Background Checks page.
What is DISA Global Solutions?
DISA Global Solutions, Inc. is a Houston-based employment screening and workplace-compliance company founded in 1986. It administers drug and alcohol testing, background checks, and Department of Transportation compliance programs for employers, and it says it runs more than 2.5 million drug tests a year for more than 55,000 client companies, with roughly 1,500 employees as of October 2024. DISA has grown mostly by acquisition. Its publicly announced deals include Drug Screens Etc. in 2008, Operating Tax Systems in 2013, Global HR Research in November 2022, Crimcheck in December 2022, SIGNUM Consulting in 2023, Validata Group and CastleBranch in 2024, and American DataBank in February 2025. Audax Private Equity acquired DISA in September 2022, and no later change of control has been reported.
DISA, Global HR Research, and the other names on your paperwork
Workers routinely get a bad result from DISA without ever seeing the word "DISA." Because of the acquisitions above, the same corporate family operates under several names, and DISA has appeared in federal court dockets doing business as Global HR Research — and in at least one case with Global HR Research, Inc. named as a separate co-defendant. If your paperwork says Global HR Research or GHRR, start with our Global HR Research background check errors page, then come back here if a drug test or a consortium status is also involved.
Two more names matter. DISA's own return-to-duty page routes "Contact MRO" to University Services (University MRO, LLC) in Feasterville-Trevose, Pennsylvania, which means the Medical Review Officer who verifies your test result is generally not a DISA employee — University Services appears as a co-defendant alongside DISA in six FCRA cases. And DISA's consortium programs sit on top of the North American Substance Abuse Program (NASAP) database, which DISA describes as maintained by the Health and Safety Council together with other approved third-party administrators. Write down every name that appears on your notice; a dispute sent to the wrong entity is a dispute that goes nowhere.
How to contact DISA Global Solutions
DISA splits its consumer channels by purpose, and the FCRA dispute channel is the narrowest of them:
- FCRA dispute (report accuracy): online form only, at disa.com/contact/bg-dispute/ — it asks for your name, date of birth, full Social Security number, phone, email, full address, order ID if you have one, the client company's name, the approximate report date, and a description of the dispute
- Request a copy of your file: disa.com/contact/bg-copy/, with the same fields
- General applicant help: disa.com/contact/applicant-assistance/, which also links a downloadable individual rights request form
- Main phone: 281-673-2400 (the number the CFPB's list and DISA's own privacy policy both give)
- Return-to-duty support: 281-673-2390 — disa.com/contact/rtd/
- Medical Review Officer: University Services, 4 Neshaminy Interplex Drive, Feasterville-Trevose, PA 19053, (800) 624-3784
Here is what DISA does not publish, and we checked carefully: there is no dispute mailing address, no dispute phone number, no dispute email address, no stated turnaround time, and no statement of who is allowed to file a dispute. The CFPB's list of consumer reporting companies says DISA will provide one free screening report on request if it has a file on you; we could find no free-disclosure statement anywhere on DISA's own site. That gap matters. Submit through the form, screenshot the confirmation, and keep a dated copy of everything you sent, because you may be the only person holding a record of the dispute.
Which DISA address should you use?
Three authoritative sources give three different addresses, and one of them is the address a consumer is most likely to rely on:
| Address | Where it comes from |
|---|---|
| 10900 Corporate Center Dr, Suite 250, Houston, TX 77041 | The CFPB's 2025 list of consumer reporting companies |
| 11740 Katy Freeway, Suite 900, Houston, TX 77079 | The Texas Comptroller's franchise-tax record, DISA's own privacy policy (updated April 2025), and DISA's data-breach notice letter |
| 17592 E. 17th Street, Suite 300, Tustin, CA 92780 | A second address given in DISA's own privacy policy |
Two DISA-controlled sources say Katy Freeway; the federal directory says Corporate Center Drive. We are not able to resolve the conflict from public records, and we are not going to guess for you. The practical consequence is real: a certified letter sent to a stale address can sit undelivered while your dispute clock runs. If you mail anything, send it to more than one of these addresses, use certified mail with return receipt, and submit the online form as well so there is a timestamped electronic record.
Common DISA errors we see
- A drug-screen result reported as positive after a collection, chain-of-custody, or laboratory handling failure
- A phantom "no-show" or "mis-marked" random test recorded against you — and a recorded refusal is generally treated the same as a positive
- Consortium status wrongly flipped to "Inactive," so a new employer's database lookup turns you away before anyone speaks to you
- Your file mixed with another worker's through name, date-of-birth, or Social Security number matching — DISA's own help center addresses workers who have no Social Security number at all, which is exactly where mismatches begin
- An "invalid" or adulterated designation you were never given a fair chance to challenge
- Criminal-record, employment, or education entries that belong to someone else, or that were expunged, sealed, or dismissed, coming through the background-screening businesses DISA acquired
- Results you cannot even see, because DISA limits release of actual test results to the paying company's designated representative and to the employee who was tested
- A DOT Clearinghouse entry that is a duplicate or a data-entry error rather than a real violation
We want to be direct about who this page is for. It is for the worker whose specimen was mishandled, whose file was mixed with someone else's, whose result was misreported or misclassified, or who was never given the split-specimen right the regulations guarantee. It is not for someone trying to beat an accurate positive test.
The consortium problem: a status that follows you between employers
This is the DISA-specific harm almost no one explains. In an industrial contractor consortium, your testing status lives in a shared database rather than in one employer's file. DISA's own help center puts it plainly: a worker stays "Active" on the NASAP database as long as he or she does not miss a random test or test non-negative, regardless of who the worker's employer is. When you show up at a new contractor, that contractor runs a lookup. If the database says "Inactive," you get retested and the employer has to contact the third-party administrator to find out why.
So an erroneous status flag is not a one-employer problem. It is a portable barrier that moves with you across an entire industry — DISA runs multiple parallel consortium programs and claims more than 20,000 participating contractors. If you keep getting turned away at the gate and no one will tell you why, that pattern is worth investigating as a reporting error, not accepting as bad luck.
How a DISA error hurts you
Screening results usually land after you have already been offered the job, sometimes after you have quit your last one. A wrong result does not just cost you that position: in safety-sensitive and industrial work it can pull you out of the labor pool entirely, because the next employer's first step is the same database or the same testing program. Workers we talk to describe losing months of income, losing a Commercial Driver's License livelihood, and being unable to explain to a recruiter what happened because they were never shown the underlying result. The FCRA exists precisely because that kind of harm follows from a piece of paper nobody let you read.
The three-door problem: three systems, three deadlines
If you got a bad result through DISA, the most valuable thing you can do in the first week is figure out which problem you have. These three processes are separate. They are decided by different people, they fix different things, and using one does not preserve your rights under the others.
| Door | What it can fix | Who decides | Deadline |
|---|---|---|---|
| FCRA dispute | Accuracy or completeness of what DISA reported about you | DISA, as a consumer reporting agency | DISA publishes no timeline; the FCRA generally gives a reporting agency 30 days to reinvestigate |
| Split-specimen request (49 CFR 40.171) | A DOT-regulated drug test result you believe is wrong | The Medical Review Officer | 72 hours from notification |
| Clearinghouse petition (49 CFR 382.717) | Administrative errors in FMCSA Clearinghouse data | FMCSA | 45 days for a response; 14 days if expedited; administrative review within 30 days of a request |
Door one — the FCRA dispute
This is the right door when DISA reported something inaccurate or incomplete about you: the wrong person's record, a stale or duplicated entry, a status that does not match the facts, or a result attributed to the wrong worker. It goes through DISA's online dispute form, and as noted above, that form is the only published channel. Do this in addition to anything else you file, because it is the route that creates FCRA obligations and an FCRA paper trail.
Door two — the 72-hour split-specimen request
If your test was DOT-regulated, federal rules give you a right that expires almost immediately. Under 49 CFR 40.171, an employee has 72 hours from the time of notification to ask the Medical Review Officer to have the split specimen tested. The request may be verbal or in writing, the MRO cannot arbitrarily deny it, and a missed deadline can be excused only with documentation of circumstances that unavoidably prevented you from making contact. One hard limitation you need to know: there is no split specimen testing for an invalid result. Because DISA routes the MRO function to University Services, the 72-hour request generally goes to that company, not to DISA. Ask for the MRO's name and direct number the moment you are notified, and make the request the same day.
Door three — the FMCSA Clearinghouse petition
If you hold a CDL, a violation entry in the FMCSA Drug and Alcohol Clearinghouse can bar you from safety-sensitive work nationwide. Under 49 CFR 382.717, a driver may petition FMCSA to correct Clearinghouse information — but the scope is narrow, and this is the part most websites get wrong. The rule covers administrative errors, such as data-entry mistakes or a duplicate report of a positive test; the addition of documentary evidence that a traffic citation did not lead to a conviction; and removal of employer reports that failed to comply with reporting requirements. Petitioners may not contest the accuracy of test results, test refusals, or other violation information under that section. FMCSA responds within 45 days of a complete petition, or 14 days for expedited treatment, with administrative review no later than 30 days after a request for review. One caution specific to this page: DISA describes itself as a third-party administrator for DOT compliance, but we found nothing on DISA's website stating that it is a registered Consortium/Third-Party Administrator that queries or reports violations into the Clearinghouse, so treat this section as general guidance for CDL holders rather than a statement about DISA's role.
DISA's track record with regulators
DISA has no public federal enforcement record that we could locate, and we want to describe that accurately rather than dress it up.
A search of the FTC's cases and proceedings index returns no matching entry for DISA. Source A search of the CFPB's enforcement-action index returns none either. Source DISA does appear on the CFPB's 2025 list of consumer reporting companies, which is where the free-report entry and the Corporate Center Drive address come from. Source We did not sweep all fifty state attorneys general, so the honest statement is that no state enforcement action was located — not that none exists.
The private litigation picture is different. Roughly two dozen FCRA-coded federal cases name DISA, the earliest filed in 2021 in the Southern District of Texas, and the filing rate rose sharply in 2024 and 2025. Where a disposition appears at all, it is a plaintiff-side exit — several voluntary dismissals with prejudice within weeks of filing — rather than a ruling on the merits. No reported merits adjudication appears in that record.
The 2024 data breach and the 308-day notification lag
This is the largest verified consumer event in DISA's history. An unauthorized party had access to DISA systems from February 9, 2024 through April 22, 2024; DISA discovered the intrusion on April 22, 2024; and notice letters were mailed on February 21, 2025 — a gap of 308 days between discovery and notification. The Maine Attorney General's record puts the total number of people affected at 3,332,750. Source The Washington Attorney General's record lists the exposed data categories as name, Social Security number, driver's license or state ID number, financial and banking information, full date of birth, passport number, health insurance policy or ID number, and medical information. Source California's breach registry carries the filing as well. Source DISA's own pre-notification statement adds the category that makes this breach distinctive for workers: the affected data may include drug testing information. Source
Three practical points. First, the remediation DISA offered — twelve months of credit monitoring with identity-theft insurance — carried an enrollment deadline of June 30, 2025, which has passed. Second, DISA hosts no public breach notice on its own website; we scanned its sitemap and the obvious incident URLs and found nothing, which means a worker who suspects a problem cannot confirm it from the company that holds the data. Third, one oddity worth flagging rather than quietly fixing: the Maine record lists the notice date as February 21, 2024, a year before the discovery date in the letter itself. It is almost certainly a typographical error for 2025, but we report it as it appears.
The breach class action is Duiker v. DISA Global Solutions, Inc., No. 4:25-cv-00821 (S.D. Tex.), filed February 25, 2025, with a consolidation order entered March 28, 2025 bringing related cases together. Source The public docket record we reviewed ends in April 2025, so the current posture of that case is not confirmed here. We also want to be clear about something the coverage blurred: the threat actor has not been publicly named, and DISA has not admitted paying a ransom. We do not assert that it did.
Zero CFPB complaints is a routing artifact, not a clean record
DISA does not appear in the CFPB's consumer complaint database at all — not as a company you can select, and not in a full-text search of millions of records. That is not a favorable statistic, and it should not be read as one. The same database indexes other employment-screening companies without difficulty, so the endpoint works. The likeliest explanation is routing: a worker who fails a drug screen does not think of it as a credit-reporting problem, so the complaint is never filed with the CFPB, or it is filed against the employer instead. Zero complaints sitting alongside two dozen FCRA lawsuits tells you where these disputes actually go — into court, not into the complaint database. If you file a CFPB complaint anyway, describe DISA by name in the narrative so the record exists.
Your rights under the Fair Credit Reporting Act
DISA must follow the FCRA. It must use reasonable procedures to assure maximum possible accuracy of what it reports about you (§1681e(b)); it must reinvestigate the items you dispute rather than simply re-confirming its own file (§1681i); public-record information reported for employment purposes must be complete and up to date (§1681k); and before an employer takes adverse action based on the report, you must be given a copy of the report and a summary of your rights (§1681b(b)(3), the pre-adverse-action requirement). That last one is often the fastest problem to spot: if you learned about the result only after the offer was already gone, ask when the employer sent you the report.
How to dispute a DISA background check
- If a DOT drug test is involved, act on the 72-hour clock first — call the Medical Review Officer and request the split specimen test the same day you are notified, then confirm it in writing.
- Ask the employer for the copy of the report and the summary of rights it is required to give you, and ask DISA for your file through its file-copy request.
- Write down every inaccuracy and gather proof — collection paperwork, lab documentation, court dispositions, employment records, or identification showing the record is not yours.
- Submit the dispute through DISA's online dispute form, save the confirmation, and keep a dated copy of everything you sent.
- Ask the employer to hold its decision while the dispute is investigated — and if it is not corrected, or the report already cost you the job, contact an FCRA attorney.
This information is general and is not legal advice for your specific situation.
Did an inaccurate DISA background check cost you a job?
DISA's screening reports are consumer reports under the FCRA, and DISA has to follow strict accuracy rules. When the report is wrong — the wrong person, a mishandled specimen, a phantom refusal, a status flag that does not match the facts — and it costs you work, you may be entitled to money damages.
Deadlines in this area are short and they do not wait for you to figure out which system applies. If you were notified of a result in the last several days, call us today, and call the Medical Review Officer today as well. Our case review is free.
How The Kim Law Firm helps
We are consumer-protection lawyers who handle FCRA cases nationwide. We help people whose DISA file is inaccurate — a specimen that was mishandled, a file mixed with another worker's, a result misreported or misclassified, a consortium status that is simply wrong, or a split-specimen right that was denied. We do not help people trying to hide an accurate record or an accurate positive test.
Admitted in Pennsylvania and New Jersey; available to appear pro hac vice in other federal courts.
What we do is unglamorous and it works: we get the file, we reconstruct the chain of custody and the reporting trail, we identify every entity involved — DISA, the Medical Review Officer, the consortium administrator, the employer — and we pursue the correction and any damages. You do not pay unless we win.
Drug and alcohol testing results as consumer report content
A failed or disputed test does not stay between you and the laboratory. When a screening company administers testing for an employer and reports the outcome, that outcome becomes part of a consumer report, with all the consequences that follow: it can be sold to another employer, it can sit in a database for years, and it is subject to the same accuracy obligations as a criminal record. Specimen mix-ups, chain-of-custody gaps, prescription medications recorded as positives and refusals logged for missed appointments all end up on the same line.
- Certiphi Screening — part of Vertical Screen, widely used for healthcare and professional screening.
- ClearStar — a Georgia company providing criminal, medical and drug screening to employers.
- Employment Background Investigations — a Maryland screener whose services include drug screening alongside record searches.
- Cisive — a New York screener operating the healthcare-screening brand PreCheck.
- Sterling — a national vendor bundling testing with employment screening for large employers.
Ask for the full testing record: the collection documentation, the laboratory result, the confirmation test and the medical review officer's determination. A positive that was never confirmed, a result attributed to the wrong specimen, or a legitimate prescription that the review process should have resolved is an inaccuracy in a consumer report and disputable as one. Programs run under Department of Transportation rules have their own correction procedures, and using both routes is usually faster than choosing between them.
Screened by a different company? We also handle HireRight background check errors, Sterling background check errors, Checkr background check errors, and First Advantage background check errors — and you can start with our overview of the major background check companies.
Frequently asked questions
How do I dispute a DISA background check?
Get the report from the employer or request your file from DISA, identify each inaccuracy, and submit a dispute through DISA's online dispute form with your supporting documents. Save the confirmation. DISA publishes no dispute mailing address, phone number, or timeline, so your own records may be the only proof the dispute happened.
DISA says my file is still processing — can a delay violate the FCRA?
It can. The FCRA generally requires a reinvestigation within about 30 days, and an employer that leaves an offer in limbo while a wrong report sits uncorrected can create its own exposure. Document each date you were told to keep waiting.
I think my drug test result is wrong — is that an FCRA dispute or something else?
It may be both, and the deadlines are very different. If the test was DOT-regulated, you have 72 hours from notification to ask the Medical Review Officer for a split-specimen test under 49 CFR 40.171 — and there is no split-specimen testing for an invalid result. Separately, how the result was reported about you can be an FCRA problem. Do not let the 72-hour clock run while you are working on the FCRA side.
Can I sue DISA for a background check error?
Possibly. If DISA reported inaccurate information, failed to reinvestigate a dispute properly, or the FCRA's adverse-action rules were ignored and you were harmed, you may have a claim. Whether the drug-test regulations were also violated is a separate question we can look at in the same review.
What if a DISA mistake already cost me the job?
That concrete loss is exactly what the FCRA is meant to address. Keep the offer letter, the withdrawal notice, the report, and any correspondence, and contact us — lost wages and other damages may be recoverable.
Is the case review really free?
Yes. There is no charge and no obligation, and you pay nothing unless we win.
Where we practice, and what to do if you are somewhere else
The Kim Law Firm is licensed in Pennsylvania and New Jersey, and that is where we handle matters directly.
The Fair Credit Reporting Act is a federal statute. It applies the same way in every state, it is enforced in federal court, and the deadlines and remedies do not change when you cross a state line. So the answer to "does this apply to me in Ohio" is yes — but the answer to "can you represent me in Ohio" depends on the case and on where it would be filed.
If you are outside Pennsylvania and New Jersey, contact us anyway. Some matters can be handled from here. Some are better sent to a consumer lawyer admitted where you are, and we will tell you that plainly rather than let a deadline run while you wait. Either way you will get an answer, and the review costs nothing.
The one thing that does not wait is the clock. A claim under the Act generally must be brought within two years of the date you discover the violation, and in no event more than five years after the violation occurred. Finding out late does not extend the outside limit.
Get a No-Cost Evaluation of Your Case Today
You don’t pay unless we win. Find out in minutes whether you have a claim.
Get Your Free Case Review
Takes 60 seconds. A case manager will call you within 1 business day.
If a background check error has cost you a job, an apartment or a license, our background check lawyer page sets out what a Fair Credit Reporting Act claim requires, who is liable, and the four documents to send us. If you are asking whether you can sue a background check company, that page covers what the Fair Credit Reporting Act allows you to recover and how long you have to file.
