Almost 400,000 Medicaid beneficiaries in the District of Columbia have had personal and protected health information exposed online, according to a recent disclosure by DC’s Medicaid agency. On July 21, 2026, the District of Columbia Department of Health Care Finance (DHCF) said it discovered two reports had been published on its website that exposed sensitive data to unauthorized individuals.
The reports showed aggregate statistics related to Medicaid and the DC Healthcare Alliance (Alliance) programs, including enrollment counts and other aggregate data. While only aggregate statistics were displayed on screen, the underlying personal information that supported the reports was contained in hidden fields that could potentially be accessed by unauthorized individuals.
When DHCF learned about the issue, the reports were immediately removed from its website, and an investigation was launched to determine the extent to which personal data had been exposed. The investigation determined that the personal and protected health information of 399,086 Medicaid and DC Healthcare Alliance beneficiaries may have been accessed by unauthorized individuals, including the following data elements: Medicaid ID number, date of birth, provider name, race, gender, ward, or ethnicity.
Beneficiary names were not accessible, nor were Social Security numbers or financial account information, which limits the potential for data misuse. The reports were accessible on the DHCF website between 2023 and July 2026, and the data related to individuals enrolled in the Medicaid or Alliance programs between those dates. Get The FREE HIPAA Compliance Checklist Immediate Delivery of Checklist Link To Your Email Address Please enable JavaScript in your browser to complete this form.
Business Email * Name * First Last Number * Company Name * Get Free Checklist Please Enter Correct Email Address Your Privacy Respected HIPAA Journal Privacy Policy The incident was determined to be a reportable data breach under the Health Insurance Portability and Accountability Act (HIPAA), and the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) was notified about the data breach on September 3, 2026.
The data breach has been added to the OCR data breach portal in the past couple of days. Individual notification letters are being mailed to all affected individuals, and DHCF said it has taken steps to strengthen internal processes to ensure that similar incidents are prevented in the future. The post DC Medicaid Agency Notifies 400,000 Beneficiaries About Data Exposure appeared first on The HIPAA Journal .
Originally published at hipaajournal.com


