DC DHCF (28 Sep notice): ~399k Medicaid/Alliance beneficiaries — website reports exposed hidden PII (found 21 Jul)
District of Columbia Department of Health Care Finance (DHCF) public notice (page dhcf-data-incident; SecurityWeek amplified 28 September 2026) states that on 21 July 2026 DHCF learned two reports on its website contained hidden personal information reachable by unauthorised users. Reports were meant to show only aggregate enrollment/statistics; underlying PII supporting those reports may have been reachable between 2023 and July 2026. Exposed fields may have included Medicaid ID numbers, date of birth, provider name, race, gender, ward, or ethnicity; DHCF says beneficiary names, Social Security numbers, and financial account information were not included. Not a hacking incident — misconfigured public reports. DHCF removed the reports immediately, began an internal review, and is mailing individual notices; enrollees in Medicaid or DC Healthcare Alliance between 2023 and July 2026 may call 1-833-687-5424. SecurityWeek cites HHS OCR portal figure of 399,086 people affected. DHCF says it has no reason to believe the data was misused. Primary: DHCF notice; wire: SecurityWeek 28 Sep.
- Product
- DC DHCF public website statistical reports (Medicaid / DC Healthcare Alliance)
- Versions
- n/a (misconfigured public reports with hidden underlying PII; not a product CVE)
- Exploited in Australia?
- no
- Patch to
- Reports removed from website; DHCF reviewing/strengthening internal processes. Affected or unsure beneficiaries (enrolled 2023–Jul 2026): contact DHCF 1-833-687-5424; monitor accounts/credit; consider fraud alerts/security freezes per DHCF notice. Operators of public analytics: ensure aggregate views cannot expose underlying row-level PII.
Primary: DHCF — Data Incident public notice (Medicaid / DC Healthcare Alliance) · Vendor: District of Columbia Department of Health Care Finance (DHCF) · SecurityWeek — DC Health Agency Exposes 400,000 Beneficiary Records (28 Sep 2026)
