INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
DC Medicaid Agency Exposes 400,000 Beneficiary Records Due to Data
| 2026-09-30 11:34 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
On July 21, 2026, the District of Columbia Department of Health Care Finance (DHCF) discovered two reports had been published on its website that exposed sensitive data to unauthorized individuals. The reports showed aggregate statistics related to Medicaid and the DC Healthcare Alliance programs, including enrollment counts and other aggregate data. This incident affected approximately 399,086 Medicaid beneficiaries in the District of Columbia who may have had their personal information accessed by unauthorized individuals between July 2023 and July 2026. The attack worked by exploiting a vulnerability that allowed sensitive data to be displayed on screen while remaining hidden in underlying fields, which could potentially be accessed by unauthorized individuals. As of September 30, 2026, the DC Medicaid agency has notified all affected beneficiaries about the data exposure, and an investigation is ongoing to determine the extent of the breach.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
financefinance
healthhealth
Incident Timeline
July 21, 2026
Threat actors exploited vulnerabilities in DHCF's website to publish two reports containing sensitive personal information of Medicaid beneficiaries.
Click on any entity below to view its context and source!
industry
Health
On July 21, 2026, the District of Columbia Department of Health Care Finance (DHCF) said it discovered two reports had been published on its website that exposed sensitive data to unauthorized individuals.
industry
Finance
On July 21, 2026, the District of Columbia Department of Health Care Finance (DHCF) said it discovered two reports had been published on its website that exposed sensitive data to unauthorized individuals.
organisation
DHCF
On July 21, 2026, the District of Columbia Department of Health Care Finance (DHCF) said it discovered two reports had been published on its website that exposed sensitive data to unauthorized individuals.
September 3, 2026
The Department of Health and Human Services' Office for Civil Rights was notified about a reportable data breach on September 3, 2026.
Click on any entity below to view its context and source!
industry
Health
The incident was determined to be a reportable data breach under the Health Insurance Portability and Accountability Act (HIPAA), and the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) was notified about the data breach on September 3, 2026.
tactic
Data Breach
The incident was determined to be a reportable data breach under the Health Insurance Portability and Accountability Act (HIPAA), and the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) was notified about the data breach on September 3, 2026.
organisation
the Health Insurance Portability
The incident was determined to be a reportable data breach under the Health Insurance Portability and Accountability Act (HIPAA), and the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) was notified about the data breach on September 3, 2026.
organisation
the Department of Health and Human Services
The incident was determined to be a reportable data breach under the Health Insurance Portability and Accountability Act (HIPAA), and the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) was notified about the data breach on September 3, 2026.
organisation
HHS) Office for Civil Rights
The incident was determined to be a reportable data breach under the Health Insurance Portability and Accountability Act (HIPAA), and the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) was notified about the data breach on September 3, 2026.
organisation
OCR
The incident was determined to be a reportable data breach under the Health Insurance Portability and Accountability Act (HIPAA), and the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) was notified about the data breach on September 3, 2026.
2026/09/21
The US Department of Health and Human Services added the DC Healthcare Data Center breach to its data breach portal on September 21, 2026.
Click on any entity below to view its context and source!
tactic
Data Breach
HHS added DHCF to its data breach
portal
late last week.
September 28, 2026
Nearly 400,000 DC Medicaid and Healthcare Alliance beneficiaries' personal data may have been exposed through reports published on a public website.
Click on any entity below to view its context and source!
general_metric
400,000 DC Agency Notifies
Nearly 400,000 Medicaid Beneficiaries Caught in Medicaid and DC Healthcare Alliance Data Exposure
Pierluigi Paganini
September 28, 2026
Nearly 400,000 DC Medicaid and Healthcare Alliance beneficiaries may have had personal data exposed through reports published on a public website.
industry
Healthcare
Nearly 400,000 Medicaid Beneficiaries Caught in Medicaid and DC Healthcare Alliance Data Exposure
Pierluigi Paganini
September 28, 2026
Nearly 400,000 DC Medicaid and Healthcare Alliance beneficiaries may have had personal data exposed through reports published on a public website.
organisation
Healthcare Alliance
Nearly 400,000 Medicaid Beneficiaries Caught in Medicaid and DC Healthcare Alliance Data Exposure
Pierluigi Paganini
September 28, 2026
Nearly 400,000 DC Medicaid and Healthcare Alliance beneficiaries may have had personal data exposed through reports published on a public website.
Sep 30, 2026
DC's Medicaid agency notified 400,000 beneficiaries about the exposure of their personal and protected health information online.
Click on any entity below to view its context and source!
industry
Health
DC Medicaid Agency Notifies 400,000 Beneficiaries About Data Exposure
Posted By
Steve Alder
on Sep 30, 2026
Almost 400,000 Medicaid beneficiaries in the District of Columbia have had personal and protected health information exposed online, according to a recent disclosure by DC’s Medicaid agency.
organisation
Medicaid
DC Medicaid Agency Notifies 400,000 Beneficiaries About Data Exposure
Posted By
Steve Alder
on Sep 30, 2026
Almost 400,000 Medicaid beneficiaries in the District of Columbia have had personal and protected health information exposed online, according to a recent disclosure by DC’s Medicaid agency.
organisation
DC’s Medicaid
DC Medicaid Agency Notifies 400,000 Beneficiaries About Data Exposure
Posted By
Steve Alder
on Sep 30, 2026
Almost 400,000 Medicaid beneficiaries in the District of Columbia have had personal and protected health information exposed online, according to a recent disclosure by DC’s Medicaid agency.
general_metric
400,000 DC Agency Notifies
DC Medicaid Agency Notifies 400,000 Beneficiaries About Data Exposure
Posted By
Steve Alder
on Sep 30, 2026
Almost 400,000 Medicaid beneficiaries in the District of Columbia have had personal and protected health information exposed online, according to a recent disclosure by DC’s Medicaid agency.
between 2023 and July 2026
Unauthorized users accessed Medicaid beneficiaries' records on the DHCF website between 2023 and July 2026.
between 2023 and 2026
Threat actors exploited a vulnerability in the DC Healthcare Alliance's systems to expose sensitive information of Medicaid beneficiaries enrolled between 2023 and 2026.
Click on any entity below to view its context and source!
organisation
Medicaid
According to the agency, the incident impacts Medicaid and the DC Healthcare Alliance beneficiaries who enrolled between 2023 and 2026.
industry
Healthcare
According to the agency, the incident impacts Medicaid and the DC Healthcare Alliance beneficiaries who enrolled between 2023 and 2026.
organisation
the DC Healthcare Alliance
According to the agency, the incident impacts Medicaid and the DC Healthcare Alliance beneficiaries who enrolled between 2023 and 2026.
2026/09/30
The District of Columbia Department of Health Care Finance (DHCF) notified nearly 400,000 Medicaid and DC Healthcare Alliance beneficiaries that their personal information may have been exposed in a data breach.
Click on any entity below to view its context and source!
organisation
DC Healthcare Alliance
The investigation determined that the personal and protected health information of 399,086 Medicaid and DC Healthcare Alliance beneficiaries may have been accessed by unauthorized individuals, including the following data elements: Medicaid ID number, date of birth, provider name, race, gender, ward, or ethnicity.
The District of Columbia Department of Health Care Finance is notifying nearly 400,000 Medicaid and DC Healthcare Alliance beneficiaries that their personal information may have been exposed.
organisation
Medicaid ID
The investigation determined that the personal and protected health information of 399,086 Medicaid and DC Healthcare Alliance beneficiaries may have been accessed by unauthorized individuals, including the following data elements: Medicaid ID number, date of birth, provider name, race, gender, ward, or ethnicity.
organisation
the US Department of Health and Human Services
The agency informed the US Department of Health and Human Services (HHS) that 399,086 people were affected.
DHCF
reported
the breach to the US Department of Health and Human Services, stating that 399,086 people were affected.
organisation
HHS
The agency informed the US Department of Health and Human Services (HHS) that 399,086 people were affected.
organisation
DC Health Agency
DC Health Agency Exposes 400,000 Beneficiary Records.
data_breach
400,000 Beneficiary Records
DC Health Agency Exposes 400,000 Beneficiary Records.
organisation
DHCF
The District of Columbia Department of Health Care Finance (DHCF) is notifying nearly 400,000 people that their personal information was potentially compromised in a data breach.
DHCF
reported
the breach to the US Department of Health and Human Services, stating that 399,086 people were affected.
organisation
Medicaid
Nearly 400,000 Medicaid Beneficiaries Caught in Medicaid and DC Healthcare Alliance Data Exposure.
organisation
Medicaid Beneficiaries Caught
Nearly 400,000 Medicaid Beneficiaries Caught in Medicaid and DC Healthcare Alliance Data Exposure.
organisation
DC Healthcare Alliance Data Exposure
Nearly 400,000 Medicaid Beneficiaries Caught in Medicaid and DC Healthcare Alliance Data Exposure.
organisation
DC Medicaid Agency
DC Medicaid Agency Notifies 400,000 Beneficiaries About Data Exposure.
organisation
the DC Healthcare Alliance (Alliance
The reports showed aggregate statistics related to Medicaid and the DC Healthcare Alliance (Alliance) programs, including enrollment counts and other aggregate data.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, data breach)
organisation
Social Security
Beneficiary names were not accessible, nor were Social Security numbers or financial account information, which limits the potential for data misuse.
No Social Security numbers, names, or financial information were compromised.
Exposed data may have included Medicaid IDs, dates of birth, provider names, race, gender, ward and ethnicity, but not names, Social Security numbers or financial information.
threat_actor
ShinyHunters
ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report
Related:
BigCommerce Data Stolen via Ribon Apps Hack
Related:
organisation
BigCommerce Data Stolen
ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report
Related:
BigCommerce Data Stolen via Ribon Apps Hack
Related:
organisation
Equifax
Under U.S. law, impacted users can get one free credit report each year from Equifax, Experian and TransUnion.
organisation
TransUnion
Under U.S. law, impacted users can get one free credit report each year from Equifax, Experian and TransUnion.
Tactical Metrics
Metrics
data_breach
400,000
Beneficiary Records
Click for context!
DC Health Agency Exposes 400,000 Beneficiary Records.
Intelligence Sources
SecurityWeek
2026-09-28
DC Health Agency Exposes 400,000 Beneficiary Records
SecurityWeek
Security Affairs
2026-09-28
HIPAA Journal
2026-09-30
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T10:34
Comprehensive Tactical Telemetry
Highly Correlated Entities
24x
organisation
Identified Entity
Medicaid
entity
7x
timeline
Temporal Reference
Sep 30, 2026
date
3x
industry
Targeted Sector
Health
sector
Contextual Telemetry
Context Block
6 METRICS
general metric
Dc Agency Notifies
400,000
dc agency notifies
general metric
Healthcare Alliance
399,086
healthcare alliance
tactic
Cyber Operation Type
Data Breach
tactic
target region
Target Country
United States
country
data breach
Beneficiary Records
400,000
beneficiary records
threat actor
APT Group
ShinyHunters
actor
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.