Nearly 400,000 Medicaid Beneficiaries Caught in Medicaid and DC Healthcare Alliance Data Exposure
Nearly 400,000 Medicaid Beneficiaries Caught in Medicaid and DC Healthcare Alliance Data Exposure

Nearly 400,000 DC Medicaid and Healthcare Alliance beneficiaries may have had personal data exposed through reports published on a public website.
The District of Columbia Department of Health Care Finance is notifying nearly 400,000 Medicaid and DC Healthcare Alliance beneficiaries that their personal information may have been exposed. The incident affects people who enrolled between 2023 and 2026. A cyberattack did not cause the breach.
DHCF reported the breach to the US Department of Health and Human Services, stating that 399,086 people were affected.
In July, DHCF discovered that two reports published on its website contained hidden personal information that could be accessed by unauthorized individuals. The exposed data included Medicaid IDs and other beneficiary information.
“On July 21, 2026, DHCF learned that two reports on DHCF’s website contained hidden personal information that could be accessed by people who did not have permission to view it. These reports were intended to display only summary information about groups of people, such as enrollment counts and other statistics, and did not show anyone’s personal details on the screen.” reads the incident notice published by DHCF.
“However, underlying personal information that supported these reports may have been reachable by unauthorized users between 2023 and July 2026.”
DHCF removed the affected reports after discovering the issue, launched a review and began strengthening its internal processes. Exposed data may have included Medicaid IDs, dates of birth, provider names, race, gender, ward and ethnicity, but not names, Social Security numbers or financial information.
DHCF said the risk of misuse is lower because the exposed information did not include Social Security numbers or financial account details.
“Because the information that could have been reached did not include Social Security numbers or financial account information, it is less likely that the information connected to you, your child, or your family member will be used in the wrong way,” reads the data breach otification letter.
The agency said it has no evidence the exposed data was accessed or misused, but urged victims to remain alert for identity theft and fraud. DHCF removed the reports, launched an internal investigation and conducted system checks after discovering the exposure.
“DHCF has no reason to believe anyone looked at or used any of this information in the wrong way, but it is always advisable to remain vigilant against the potential for identity theft and fraud and to monitor your accounts and credit reports for any suspicious activity.” states DC Healthcare Alliance.
Under U.S. law, impacted users can get one free credit report each year from Equifax, Experian and TransUnion. They can check their reports regularly for suspicious activity or signs of identity theft. They can request them through AnnualCreditReport.com or by phone. Users can also stagger requests to check one report every four months.
Users can also place a free one-year fraud alert on their credit file. It asks lenders to verify your identity before opening new accounts or changing existing ones. Contacting any one of the three credit bureaus will automatically notify the other two.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, data breach)
