DC Health Department Discloses 400,000 Beneficiary Records in Data Leak
DC Health Agency Discloses Data Breach Affecting 400,000 Beneficiaries
Details of the Breach
The District of Columbia Department of Health Care Finance (DHCF) has informed nearly 400,000 individuals that their personal information may have been exposed in a data breach. The incident involves Medicaid and DC Healthcare Alliance beneficiaries who enrolled between 2023 and 2026. The breach was not attributed to external hacking but resulted from two reports hosted on the agency’s website containing unsecured data.
What Data Was Exposed?
According to DHCF, the reports were designed to present aggregated statistics, such as enrollment numbers and demographic summaries, without displaying individual details. However, underlying information supporting these reports was accessible to unauthorized users between 2023 and July 2026. The compromised data includes Medicaid identification numbers, provider names, dates of birth, race, gender, ethnicity, and ward information.
Impact and Response
No Social Security numbers, full names, or financial details were included in the exposure. DHCF emphasized that the lack of sensitive identifiers like Social Security numbers or financial data reduces the risk of misuse. The agency notified the U.S. Department of Health and Human Services (HHS) of the breach, which added the incident to its public data breach portal. A total of 399,086 individuals were impacted, according to the agency.
“While DHCF stated there is no evidence of unauthorized access or exploitation of the data, it advised affected individuals to monitor for signs of identity theft or fraud. The agency removed the affected reports from its website, initiated an internal investigation, and conducted system audits to address vulnerabilities.”
Broader Implications
The breach highlights risks associated with improperly configured data disclosures, underscoring the importance of rigorous access controls and regular security reviews for public-facing systems. No further details about the technical mechanisms enabling the exposure were provided.
