INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

DC Medicaid Agency Exposes 400,000 Beneficiary Records Due to Data

| 2026-09-30 11:34 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
On July 21, 2026, the District of Columbia Department of Health Care Finance (DHCF) discovered two reports had been published on its website that exposed sensitive data to unauthorized individuals. The reports showed aggregate statistics related to Medicaid and the DC Healthcare Alliance programs, including enrollment counts and other aggregate data. This incident affected approximately 399,086 Medicaid beneficiaries in the District of Columbia who may have had their personal information accessed by unauthorized individuals between July 2023 and July 2026. The attack worked by exploiting a vulnerability that allowed sensitive data to be displayed on screen while remaining hidden in underlying fields, which could potentially be accessed by unauthorized individuals. As of September 30, 2026, the DC Medicaid agency has notified all affected beneficiaries about the data exposure, and an investigation is ongoing to determine the extent of the breach.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
Target & Sectors
NORTH_AMERICA NORTH_AMERICA financefinance healthhealth
Incident Timeline
‎July 21, 2026
Threat actors exploited vulnerabilities in DHCF's website to publish two reports containing sensitive personal information of Medicaid beneficiaries.
industry Health
industry Finance
organisation DHCF
‎September 3, 2026
The Department of Health and Human Services' Office for Civil Rights was notified about a reportable data breach on September 3, 2026.
industry Health
tactic Data Breach
organisation the Health Insurance Portability
organisation the Department of Health and Human Services
organisation HHS) Office for Civil Rights
organisation OCR
‎2026/09/21
The US Department of Health and Human Services added the DC Healthcare Data Center breach to its data breach portal on September 21, 2026.
tactic Data Breach
‎September 28, 2026
Nearly 400,000 DC Medicaid and Healthcare Alliance beneficiaries' personal data may have been exposed through reports published on a public website.
general_metric 400,000 DC Agency Notifies
industry Healthcare
organisation Healthcare Alliance
‎Sep 30, 2026
DC's Medicaid agency notified 400,000 beneficiaries about the exposure of their personal and protected health information online.
industry Health
organisation Medicaid
organisation DC’s Medicaid
general_metric 400,000 DC Agency Notifies
‎between 2023 and July 2026
Unauthorized users accessed Medicaid beneficiaries' records on the DHCF website between 2023 and July 2026.
‎between 2023 and 2026
Threat actors exploited a vulnerability in the DC Healthcare Alliance's systems to expose sensitive information of Medicaid beneficiaries enrolled between 2023 and 2026.
organisation Medicaid
industry Healthcare
organisation the DC Healthcare Alliance
‎2026/09/30
The District of Columbia Department of Health Care Finance (DHCF) notified nearly 400,000 Medicaid and DC Healthcare Alliance beneficiaries that their personal information may have been exposed in a data breach.
organisation DC Healthcare Alliance
organisation Medicaid ID
organisation the US Department of Health and Human Services
organisation HHS
organisation DC Health Agency
data_breach 400,000 Beneficiary Records
organisation DHCF
organisation Medicaid
organisation Medicaid Beneficiaries Caught
organisation DC Healthcare Alliance Data Exposure
organisation DC Medicaid Agency
organisation the DC Healthcare Alliance (Alliance
organisation SecurityAffairs
organisation Social Security
threat_actor ShinyHunters
organisation BigCommerce Data Stolen
organisation Equifax
organisation TransUnion
Tactical Metrics
Metrics
data_breach
400,000
Beneficiary Records