NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

DC Medicaid Agency Notifies 400,000 Beneficiaries About Data Exposure

Almost 400,000 Medicaid beneficiaries in the District of Columbia have had personal and protected health information exposed online, according to a recent disclosure by DC’s Medicaid agency. On July 21, 2026, the District of Columbia Department of Health Care Finance (DHCF) said it discovered two reports had been published on its website that exposed sensitive data to unauthorized individuals.

The reports showed aggregate statistics related to Medicaid and the DC Healthcare Alliance (Alliance) programs, including enrollment counts and other aggregate data. While only aggregate statistics were displayed on screen, the underlying personal information that supported the reports was contained in hidden fields that could potentially be accessed by unauthorized individuals.

When DHCF learned about the issue, the reports were immediately removed from its website, and an investigation was launched to determine the extent to which personal data had been exposed. The investigation determined that the personal and protected health information of 399,086 Medicaid and DC Healthcare Alliance beneficiaries may have been accessed by unauthorized individuals, including the following data elements: Medicaid ID number, date of birth, provider name, race, gender, ward, or ethnicity.

Beneficiary names were not accessible, nor were Social Security numbers or financial account information, which limits the potential for data misuse. The reports were accessible on the DHCF website between 2023 and July 2026, and the data related to individuals enrolled in the Medicaid or Alliance programs between those dates.

The incident was determined to be a reportable data breach under the Health Insurance Portability and Accountability Act (HIPAA), and the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) was notified about the data breach on September 3, 2026. The data breach has been added to the OCR data breach portal in the past couple of days. Individual notification letters are being mailed to all affected individuals, and DHCF said it has taken steps to strengthen internal processes to ensure that similar incidents are prevented in the future.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist