Back Securityweek DC Health Agency Exposes 400,000 Beneficiary Records
The District of Columbia Department of Health Care Finance (DHCF) is notifying nearly 400,000 people that their personal information was potentially compromised in a data breach.
According to the agency, the incident impacts Medicaid and the DC Healthcare Alliance beneficiaries who enrolled between 2023 and 2026.
The data breach was not the result of hacking. Instead, DHCF discovered in July that two reports on its website contained hidden personal information accessible to unauthorized individuals.
“These reports were intended to display only summary information groups of people, such as enrollment counts and other statistics, and did not show anyone’s personal details on the screen,” DHCF said in an incident notice .
“However, underlying personal information that supported these reports may have been reachable by unauthorized users between 2023 and July 2026,” it added.
The exposed information included Medicaid IDs, provider names, dates of birth, race, gender, ethnicity, and ward. No Social Security numbers, names, or financial information were compromised.
“Because the information that could have been reached did not include Social Security numbers or financial account information, it is less likely that the information connected to you, your child, or your family member will be used in the wrong way,” DHCF said in notification letters sent to the impacted individuals.
The agency informed the US Department of Health and Human Services (HHS) that 399,086 people were affected. HHS added DHCF to its data breach portal late last week.
DHCF says it “has no reason to believe anyone looked at or used any of this information in the wrong way,” but urges potentially affected individuals to remain vigilant against identity theft and fraud attempts.
The agency removed the reports from its website immediately after discovering the data breach, initiated an internal review, and performed internal system checks.
Related: Astrana Health Data Breach Impacts Private, Confidential Information
Related: ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report
Related: BigCommerce Data Stolen via Ribon Apps Hack
Related: CrowdSec Confirms Source Code Stolen in Supply Chain Attack
Ionut Arghire is an international correspondent for SecurityWeek.
More from Ionut Arghire
New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining
Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court
‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration
Roundcube Webmail Vulnerability in Attackers’ Crosshairs
Kontext Security Emerges With $4 Million for AI Agent Runtime Controls
AI-Powered Campaign Targets Hundreds of Online Retailers
SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted
Astrana Health Data Breach Impacts Private, Confidential Information
Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon
Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign
New Mexico Jury Finds Liable for Deceiving Users Privacy Protections
Nvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog
Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability
Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug
Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks
China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks
Flipboard Whatsapp Whatsapp Email
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
