DC Medicaid Agency Sends Data Breach Notification to 400,000 Beneficiaries

The District of Columbia Department of Health Care Finance (DHCF) notified almost 400,000 Medicaid and DC Healthcare Alliance beneficiaries that personal and protected health information (PHI) may have been accessed by unauthorized individuals after sensitive data was exposed through reports published on the agency’s website.

Data Exposure Affected 399,086 Beneficiaries

DHCF disclosed that it posted two reports on its website that had exposed sensitive information. The reports presented aggregate statistics involving Medicaid and the DC Healthcare Alliance programs, including the number of enrollments and other aggregate data.

Although only aggregate statistics were visible on the screen, the underlying personal data used as the basis to create the reports were stored in hidden fields. Unauthorized individuals could access those hidden fields.

DHCF determined through its investigation that personal data and PHI belonging to 399,086 beneficiaries of DC Healthcare Alliance and Medicaid may have been exposed. The breached data possibly included birth dates, provider names, gender, race, ward, ethnicity, or Medicaid ID numbers. Social Security numbers, beneficiary names, and financial account details were not accessible.

Reports Were Available From 2023 Through July 2026

DHCF discovered the exposure on July 21, 2026. The agency removed the reports from its website after learning of the issue and launched an investigation into the scope of the exposure.

It was confirmed that the reports could have been accessed by anyone on DHCF’s website from 2023 to July 2026. The information contained in the reports related to individuals enrolled in the Medicaid or DC Healthcare Alliance programs during that period.

The investigation confirmed that the incident constituted a reportable data breach under the Health Insurance Portability and Accountability Act (HIPAA).

Notifications Sent by DHCF

DHCF notified the U.S. Department of Health and Human Services Office for Civil Rights (OCR) about the data breach on September 3, 2026. The breach was subsequently added to the OCR data breach portal. DHCF is mailing individual notification letters to all affected individuals.

The agency also reported that it has taken steps to strengthen its internal processes following the exposure. The stated purpose of those steps is to prevent similar incidents from occurring in the future.

The available information does not state whether any unauthorized individual actually used the exposed information for identity theft, fraud, or another purpose. The source also does not state whether DHCF identified any specific unauthorized individual who accessed the information.

Image credit: Studio Infinity 2197940660 Adobestock / logo©DHCF

Twitter Facebook LinkedIn Reddit Copy link Link copied to clipboard
Photo of author

Posted by

John Blacksmith

John Blacksmith is a journalist with several years experience in both print and online publications. John has specialised in Information technology in the healthcare sector and in particular in healthcare data security and privacy. His focus on healthcare data means he has specialist knowledge of the HIPAA regulations. John has a degree in journalism and many years experience.
Twitter
LinkedIn