The District of Columbia Department of Health Care Finance has disclosed a data incident affecting 399,086 people after discovering that two reports published on its website contained hidden personal information belonging to Medicaid and DC Healthcare Alliance beneficiaries.
The exposure was not the result of a conventional cyberattack. Instead, reports intended to display aggregate information, such as enrollment counts and statistics, contained underlying beneficiary data that could potentially be accessed by unauthorized users.
The information may have been reachable through the public-facing reports for years, from 2023 until the Department of Health Care Finance, known as DHCF, discovered the problem on July 21, 2026.
DHCF reported the incident to the U.S. Department of Health and Human Services Office for Civil Rights as affecting 399,086 individuals.
Hidden data exposed through public reports
According to DHCF’s official data incident notice, the two affected reports were designed to display only summary information about groups of beneficiaries.
Personal details were not visibly displayed when viewing the reports normally. However, DHCF discovered that underlying information supporting the reports remained accessible and could potentially be reached by people who were not authorized to view it.
The agency said the exposure affected Medicaid and DC Healthcare Alliance beneficiaries enrolled between 2023 and July 2026.
After discovering the issue, DHCF removed the reports from its website and began reviewing what happened. The agency also said it checked its systems and is strengthening internal processes intended to prevent similar exposures.
Medicaid IDs and demographic information potentially exposed
The information potentially accessible through the reports varied between beneficiaries but may have included Medicaid identification numbers, dates of birth, provider names, race, gender, ward and ethnicity.
DHCF said beneficiary names, Social Security numbers and financial account information were not included in the exposed data.
The agency’s notification letter indicates the information could relate not only to the person receiving the notice, but also to a child or a deceased family member whose information was maintained by DHCF.
While the absence of Social Security numbers and financial account information reduces some forms of identity theft risk, the exposed information remains sensitive. Medicaid identifiers combined with dates of birth, healthcare provider information and demographic details could potentially be used to make phishing or impersonation attempts more convincing.
No evidence exposed information was misused
DHCF said it has not learned that anyone improperly viewed or used the exposed information.
The agency is nevertheless mailing individual breach notifications to affected beneficiaries and has notified the U.S. Department of Health and Human Services Office for Civil Rights.
DHCF advised beneficiaries to remain vigilant for suspicious activity and review communications involving their health coverage or services. The agency also provided information about obtaining credit reports, placing fraud alerts and using security freezes as precautionary measures.
Individuals who participated in Medicaid or the DC Healthcare Alliance between 2023 and July 2026 and believe they should have received a notification can contact DHCF for additional information.
Exposure remained possible for years
The lengthy exposure window is one of the most significant aspects of the incident. DHCF says the underlying personal information may have been reachable from sometime in 2023 until the reports were removed following discovery on July 21, 2026.
The incident illustrates how sensitive information can be exposed without attackers penetrating an organization’s network. Reports and dashboards designed to present aggregate statistics can still create a data exposure if underlying records remain embedded or accessible to users of the public-facing resource.
DHCF has not said it found evidence that anyone intentionally retrieved the hidden beneficiary information during the exposure period.
The agency said it is reviewing the incident and strengthening internal processes to reduce the likelihood of similar exposures in the future.










