2026 DC DHCF — website reports exposed Medicaid/Alliance data; 399,086 people
Data compromised
Per DHCF / HHS OCR filing: Medicaid IDs, provider names, dates of birth, race, gender, ethnicity, and ward for Medicaid and DC Healthcare Alliance beneficiaries enrolled 2023–2026. No names, SSNs, or financial information. Agency says no reason to believe data was misused; risk lower without SSN/financials.
Technical writeup
Verified agency notification — District of Columbia Department of Health Care Finance (DHCF) notifying ~399,086 Medicaid and DC Healthcare Alliance beneficiaries (HHS OCR portal). Discovered July 21, 2026: two website reports meant to display only group summary statistics (enrollment counts etc.) had underlying personal fields reachable by unauthorized users from 2023 through July 2026. Not caused by a cyberattack. Fields: Medicaid IDs, provider names, DOB, race, gender, ethnicity, ward — not names, SSNs, or financial accounts. Reports removed; internal review/system checks. recordsAffected 399086; companyConfirmed true.
Root cause
Two public website reports intended to show summary stats contained reachable underlying personal data (DHCF notice; discovered Jul 21, 2026; exposure window 2023–Jul 2026). Not a hack.