LHC Group, a Lafayette, Louisiana provider of home health, hospice and home- and community-based services operating in 28 US states and the District of Columbia, has begun notifying patients about a data security incident that ran through a third-party technology vendor. The unnamed vendor supported referral management, care coordination and clinical workflows, and required access to patients' personal and protected health information to do so. LHC established on 7 April 2026 that an employee may have been the victim of a voice-phishing attack; the vendor then reported suspicious activity on its platform tied to an LHC user account. The threat actor had stolen credentials and accessed a large volume of files on the vendor's platform, including files containing protected health information, with access running from 7 April to 15 April 2026. LHC began confirming the identities of affected individuals on 9 July 2026, roughly three months after the access window closed. The data types vary by individual and include full names, addresses, dates of birth and demographic information, plus clinical summaries, treatment plans, diagnosis codes, dates of service, physician and provider information, Medicare and Medicaid numbers, health insurance information and, in limited cases, Social Security numbers and financial information. LHC disabled the compromised account, enhanced authentication and monitoring, strengthened other controls, and is offering two years of complimentary credit monitoring and identity-theft protection. Based on the breach notifications sent to state attorneys general, more than 28,000 individuals are affected, and the true total is likely higher because not all states publish resident counts. This is the second breach LHC Group has announced this year, the earlier one arising from a vendor called Doctor Alliance. The operationally important detail is the access vector: a single successful telephone call to one employee at a supplier, not an intrusion into the healthcare provider.
| Attribute | Detail |
|---|---|
| Sector | Healthcare |
| Date | 2026-09-16 |
| Source | HIPAA Journal |
| Reliability | Tier 2 |