Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-10-01 · updated: 2026-10-01 · tags: [incident, healthcare] · confidence: high · severity: high · affected_sectors: [healthcare] · au_impact: false

The District of Columbia Department of Health Care Finance (DHCF) discovered on 21 July 2026 that two reports published on its public website exposed sensitive data to unauthorised individuals. The reports displayed only aggregate Medicaid and DC Healthcare Alliance statistics — enrolment counts and similar — but the personal information supporting them sat in hidden fields that could be reached by anyone viewing the page. The subsequent investigation found the personal and protected health information of 399,086 beneficiaries may have been accessed, comprising Medicaid ID number, date of birth, provider name, race, gender, ward and ethnicity. Names were not accessible, and neither were Social Security numbers or financial account details, which limits misuse potential. The reports had been reachable between 2023 and July 2026, covering people enrolled in either programme across that period. DHCF removed them immediately, determined the incident was reportable under HIPAA, and notified the HHS Office for Civil Rights on 3 September 2026; the breach has since appeared on the OCR portal and individual letters are being mailed.

Attribute Detail
Sector Healthcare
Date 2026-10-01
Source HIPAA Journal
Reliability Tier 2