The District of Columbia Department of Health Care Finance (DHCF) is notifying approximately 400,000 individuals about a potential data exposure. The incident affects beneficiaries of Medicaid and the DC Healthcare Alliance who were enrolled between 2023 and 2026.
The data exposure was not caused by a hacking incident. Instead, DHCF discovered in July that two reports published on its website contained underlying personal information that was accessible to unauthorized individuals. These reports were intended to display only summary statistics, not personal details, on screen.
The exposed data included Medicaid IDs, provider names, dates of birth, race, gender, ethnicity, and ward information. DHCF confirmed that Social Security numbers, names, or financial information were not compromised in this incident. The agency stated that the absence of Social Security numbers or financial data makes it less likely for the information to be misused.
Upon discovering the issue, DHCF immediately removed the affected reports from its website, initiated an internal review, and performed system checks. The agency reported the incident to the US Department of Health and Human Services (HHS), which subsequently added DHCF to its data breach portal. While DHCF has no indication that the information was accessed or misused, it advises affected individuals to remain vigilant against potential identity theft and fraud.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The District of Columbia Department of Health Care Finance (DHCF) exposed personal information for nearly 400,000 Medicaid and DC Healthcare Alliance beneficiaries. The exposure resulted from hidden data in website reports, not hacking, and included Medicaid IDs, dates of birth, race, gender, ethnicity, and ward.