Securityweek DHCF Data Incident Exposes Personal Information of 400,000 Beneficiaries
Article Content
- •Nearly 400,000 beneficiaries potentially affected by data exposure.
- •Incident discovered on July 21, 2026, involving unauthorized access to hidden personal information.
- •No Social Security numbers or financial data were compromised.
The District of Columbia Department of Health Care Finance (DHCF) reported a data incident affecting nearly 400,000 beneficiaries of Medicaid and the DC Healthcare Alliance. The breach was discovered on July 21, 2026, when DHCF found that two reports on its website contained hidden personal information accessible to unauthorized users from 2023 to July 2026. The exposed data included Medicaid IDs, provider names, dates of birth, race, gender, ethnicity, and ward, but did not include Social Security numbers or financial information. DHCF has removed the reports from its website and initiated an internal review to prevent future incidents. The agency has informed the U.S. Department of Health and Human Services (HHS) about the breach, which has been added to its data breach portal. DHCF has stated that it has no reason to believe the information was misused, but it advises individuals to remain vigilant against identity theft.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track District Of Columbia Department Of Health Care Finance and CVE-2026-65660 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerabilities in Citrix NetScaler Under Active Exploitation On September 26, 2026, security firm watchTowr reported two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances, allowing remote code execution (RCE) and actively exploited in the wild. Citrix has confirmed the existence of these vulnerabilities, tracked as CVE-2026-88771 and…