Skip to content
DC Health Agency Exposes 400,000 Beneficiary Records

DC Health Agency Exposes 400,000 Beneficiary Records

Securityweek •Ionut Arghire • September 28, 2026

The District of Columbia Department of Health Care Finance (DHCF) is notifying nearly 400,000 people that their personal information was potentially compromised in a data breach.

According to the agency, the incident impacts Medicaid and the DC Healthcare Alliance beneficiaries who enrolled between 2023 and 2026.

The data breach was not the result of hacking. Instead, DHCF discovered in July that two reports on its website contained hidden personal information accessible to unauthorized individuals.

“These reports were intended to display only summary information groups of people, such as enrollment counts and other statistics, and did not show anyone’s personal details on the screen,” DHCF said in an incident notice .

“However, underlying personal information that supported these reports may have been reachable by unauthorized users between 2023 and July 2026,” it added.

The exposed information included Medicaid IDs, provider names, dates of birth, race, gender, ethnicity, and ward. No Social Security numbers, names, or financial information were compromised.

“Because the information that could have been reached did not include Social Security numbers or financial account information, it is less likely that the information connected to you, your child, or your family member will be used in the wrong way,” DHCF said in notification letters sent to the impacted individuals.

The agency informed the US Department of Health and Human Services (HHS) that 399,086 people were affected. HHS added DHCF to its data breach portal late last week.

DHCF says it “has no reason to believe anyone looked at or used any of this information in the wrong way,” but urges potentially affected individuals to remain vigilant against identity theft and fraud attempts.

The agency removed the reports from its website immediately after discovering the data breach, initiated an internal review, and performed internal system checks.

Related: Astrana Health Data Breach Impacts Private, Confidential Information

Related: ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report

Related: BigCommerce Data Stolen via Ribon Apps Hack

Related: CrowdSec Confirms Source Code Stolen in Supply Chain Attack

Ionut Arghire is an international correspondent for SecurityWeek.

More from Ionut Arghire

New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining

Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court

‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration

Roundcube Webmail Vulnerability in Attackers’ Crosshairs

Kontext Security Emerges With $4 Million for AI Agent Runtime Controls

AI-Powered Campaign Targets Hundreds of Online Retailers

SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted

Astrana Health Data Breach Impacts Private, Confidential Information

Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon

Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign

New Mexico Jury Finds Liable for Deceiving Users Privacy Protections

Nvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog

Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability

Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug

Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks

China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks

Flipboard Whatsapp Whatsapp Email

Extracted Entities