Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

DC Health Agency Exposes 400,000 Beneficiary Records

The Medicaid IDs and other information of Medicaid and DC Healthcare Alliance beneficiaries were exposed.

Healthcare data breach

The District of Columbia Department of Health Care Finance (DHCF) is notifying nearly 400,000 people that their personal information was potentially compromised in a data breach.

According to the agency, the incident impacts Medicaid and the DC Healthcare Alliance beneficiaries who enrolled between 2023 and 2026.

The data breach was not the result of hacking. Instead, DHCF discovered in July that two reports on its website contained hidden personal information accessible to unauthorized individuals.

“These reports were intended to display only summary information about groups of people, such as enrollment counts and other statistics, and did not show anyone’s personal details on the screen,” DHCF said in an incident notice.

“However, underlying personal information that supported these reports may have been reachable by unauthorized users between 2023 and July 2026,” it added.

The exposed information included Medicaid IDs, provider names, dates of birth, race, gender, ethnicity, and ward. No Social Security numbers, names, or financial information were compromised.

Advertisement. Scroll to continue reading.

“Because the information that could have been reached did not include Social Security numbers or financial account information, it is less likely that the information connected to you, your child, or your family member will be used in the wrong way,” DHCF said in notification letters sent to the impacted individuals.

The agency informed the US Department of Health and Human Services (HHS) that 399,086 people were affected. HHS added DHCF to its data breach portal late last week.

DHCF says it “has no reason to believe anyone looked at or used any of this information in the wrong way,” but urges potentially affected individuals to remain vigilant against identity theft and fraud attempts.

The agency removed the reports from its website immediately after discovering the data breach, initiated an internal review, and performed internal system checks.

Related: Astrana Health Data Breach Impacts Private, Confidential Information

Related: ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report

Related: BigCommerce Data Stolen via Ribon Apps Hack

Related: CrowdSec Confirms Source Code Stolen in Supply Chain Attack

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

People on the Move

Chip Wentz has been appointed as SVP & CISO at Keurig Dr Pepper Inc.

Lumen Technologies has named Kim Keever as CSO.

Quantum Secure Encryption Corp. has appointed Joseph Hall as CIO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.