The District of Columbia Department of Health Care Finance (DHCF) disclosed that two publicly accessible web reports exposed underlying personal data for 399,086 DC Medicaid and DC Healthcare Alliance beneficiaries enrolled from 2023 to 2026. Although the reports displayed aggregate enrollment and statistical information, hidden data may have been available to unauthorized visitors from 2023 until the agency identified the issue on July 21, 2026.
The exposed fields included Medicaid IDs, dates of birth, provider names, race, gender, ethnicity, and ward; the agency said names, Social Security numbers, and financial-account information were not included. DHCF said the incident was not a cyberattack and that it has found no evidence of access or misuse, but removed the reports, began an internal review and system checks, notified affected individuals, and reported the exposure to the US Department of Health and Human Services.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
The US Department of Health and Human Services added DHCF to its data-breach portal for the exposure affecting 399,086 individuals.
DHCF discovered on July 21 that two public reports exposed hidden personal information associated with 399,086 beneficiaries enrolled between 2023 and 2026. The agency said the incident was not caused by a cyberattack and found no evidence of access or misuse.
Two publicly accessible DHCF reports contained underlying personal information for DC Medicaid and DC Healthcare Alliance beneficiaries, potentially allowing unauthorized access beginning in 2023.
Following discovery, DHCF removed the affected reports, initiated an internal review and system checks, notified affected individuals, and reported the incident to the US Department of Health and Human Services.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
5 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcesecurityweek.com
Open sourceusa.gov
Open sourcedhcf.dc.gov
Open sourcedhcf.dc.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.