Data Breaches

DC Health Agency Exposes 400,000 Beneficiary Records

The Medicaid IDs and other information of Medicaid and DC Healthcare Alliance beneficiaries were exposed.

Healthcare data breach

The District of Columbia Department of Health Care Finance (DHCF) is notifying nearly 400,000 people that their personal information was potentially compromised in a data breach.

According to the agency, the incident impacts Medicaid and the DC Healthcare Alliance beneficiaries who enrolled between 2023 and 2026.

The data breach was not the result of hacking. Instead, DHCF discovered in July that two reports on its website contained hidden personal information accessible to unauthorized individuals.

“These reports were intended to display only summary information about groups of people, such as enrollment counts and other statistics, and did not show anyone’s personal details on the screen,” DHCF said in an incident notice.

“However, underlying personal information that supported these reports may have been reachable by unauthorized users between 2023 and July 2026,” it added.

The exposed information included Medicaid IDs, provider names, dates of birth, race, gender, ethnicity, and ward. No Social Security numbers, names, or financial information were compromised.

Advertisement. Scroll to continue reading.

“Because the information that could have been reached did not include Social Security numbers or financial account information, it is less likely that the information connected to you, your child, or your family member will be used in the wrong way,” DHCF said in notification letters sent to the impacted individuals.

The agency informed the US Department of Health and Human Services (HHS) that 399,086 people were affected. HHS added DHCF to its data breach portal late last week.

DHCF says it “has no reason to believe anyone looked at or used any of this information in the wrong way,” but urges potentially affected individuals to remain vigilant against identity theft and fraud attempts.

The agency removed the reports from its website immediately after discovering the data breach, initiated an internal review, and performed internal system checks.

Related: Astrana Health Data Breach Impacts Private, Confidential Information

Related: ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report

Related: BigCommerce Data Stolen via Ribon Apps Hack

Related: CrowdSec Confirms Source Code Stolen in Supply Chain Attack

Related Content

Data Breaches

Hackers stole patient information from Clover Health Investments and AngMar Management Services in July.

Government

More than 730 cyber breaches affected over 270 million Americans last year, costing an average of $10 million per breach.

Data Breaches

The data breach affects the Defense Manpower Data Center (DMDC), which maintains personnel records for the Department of Defense.

Artificial Intelligence

A threat actor is using three AI harnesses for vulnerability research, exploitation, and attack orchestration.

Data Breaches

Hackers impersonated the company’s personnel and contacted its employees to gain access to Astrana Health’s servers.

Data Breaches

The cybercrime group is unhappy with its description in an FBI report and threatens to leak stolen information. 

Data Breaches

The attackers used a compromised BigCommerce application key held by Ribon to access customer data.

Data Breaches

The cybersecurity firm believes the data breach was the result of the May 2026 TanStack supply chain attack.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version