The District of Columbia Department of Health Care Finance (DHCF) notified almost 400,000 Medicaid and DC Healthcare Alliance beneficiaries that personal and protected health information (PHI) may have been accessed by unauthorized individuals after sensitive data was exposed through reports published on the agency’s website.
Data Exposure Affected 399,086 Beneficiaries
DHCF disclosed that it posted two reports on its website that had exposed sensitive information. The reports presented aggregate statistics involving Medicaid and the DC Healthcare Alliance programs, including the number of enrollments and other aggregate data.
Although only aggregate statistics were visible on the screen, the underlying personal data used as the basis to create the reports were stored in hidden fields. Unauthorized individuals could access those hidden fields.
DHCF determined through its investigation that personal data and PHI belonging to 399,086 beneficiaries of DC Healthcare Alliance and Medicaid may have been exposed. The breached data possibly included birth dates, provider names, gender, race, ward, ethnicity, or Medicaid ID numbers. Social Security numbers, beneficiary names, and financial account details were not accessible.
Reports Were Available From 2023 Through July 2026
DHCF discovered the exposure on July 21, 2026. The agency removed the reports from its website after learning of the issue and launched an investigation into the scope of the exposure.
It was confirmed that the reports could have been accessed by anyone on DHCF’s website from 2023 to July 2026. The information contained in the reports related to individuals enrolled in the Medicaid or DC Healthcare Alliance programs during that period.
The investigation confirmed that the incident constituted a reportable data breach under the Health Insurance Portability and Accountability Act (HIPAA).
Notifications Sent by DHCF
DHCF notified the U.S. Department of Health and Human Services Office for Civil Rights (OCR) about the data breach on September 3, 2026. The breach was subsequently added to the OCR data breach portal. DHCF is mailing individual notification letters to all affected individuals.
The agency also reported that it has taken steps to strengthen its internal processes following the exposure. The stated purpose of those steps is to prevent similar incidents from occurring in the future.
The available information does not state whether any unauthorized individual actually used the exposed information for identity theft, fraud, or another purpose. The source also does not state whether DHCF identified any specific unauthorized individual who accessed the information.
Image credit: Studio Infinity 2197940660 Adobestock / logo©DHCF









