Skip to content

Security3 publishers2 min readPublished

DC Medicaid agency's public reports carried hidden records on 399,086 people behind enrollment counts

DC's Department of Health Care Finance says two public summary reports exposed underlying records on 399,086 people. The data sat behind pages built to show enrollment counts and was reachable from 2023 until July 2026, when the agency found and pulled the reports.

The Watch · Security desk

Illustration accompanying DC Medicaid agency's public reports carried hidden records on 399,086 people behind enrollment counts

What happened

  • DHCF says the breach was not the result of hacking, and that unauthorized people could reach the personal data through the reports themselves.
  • Exposed fields included Medicaid IDs, provider names, dates of birth, race, gender, ethnicity and ward, but not Social Security numbers, names or financial data.
  • Those affected are Medicaid and DC Healthcare Alliance beneficiaries who enrolled between 2023 and 2026, and letters are going to nearly 400,000 people.
  • HHS added DHCF to its public data breach portal late last week, after the agency reported the affected count to the department.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • cost Taking two pages down ended the exposure. Because it ran for up to three and a half years, the agency now owes a breach notice to every enrollee from that period.
  • exposure The Medicaid ID was among the reachable fields, so the agency's lower-risk case, built on the absence of Social Security and bank data, does not extend to the Medicaid ID itself.
  • decision Anyone publishing aggregate statistics from personal-data systems has to test what a report delivers to a visitor, because DHCF's pages showed no personal details on screen while the data behind them was reachable.

Nothing is reachable now. After taking the reports down, DHCF started an internal review and ran internal system checks [5]. The agency dates the exposure from 2023 to July 2026 but does not give a start month [2]. That puts the window somewhere between two years and seven months and three and a half years [1].

DHCF described the failure in two sentences. "These reports were intended to display only summary information about groups of people, such as enrollment counts and other statistics, and did not show anyone's personal details on the screen," the agency said in its incident notice [1]. "However, underlying personal information that supported these reports may have been reachable by unauthorized users between 2023 and July 2026," it added [2].

Anyone checking what those pages displayed would have seen counts and statistics [1]. The personal records were in the data that supported the reports [2]. The notice does not say how a visitor would have reached that data or whether the agency's access logs go back to 2023.

That gap limits what DHCF's assurance can prove. The agency says it "has no reason to believe anyone looked at or used any of this information in the wrong way," and still urges recipients to watch for identity theft and fraud [6]. By its account this was a publishing error at one agency, and no hacking was involved [2].

The letters to enrollees lay out the agency's reasoning on risk. "Because the information that could have been reached did not include Social Security numbers or financial account information, it is less likely that the information connected to you, your child, or your family member will be used in the wrong way," DHCF wrote [3].

What to watch

  • DHCF's internal review findings, especially how the underlying records could be reached and whether access logs cover the full window from 2023.
  • Any sign that the Medicaid IDs and birth dates have surfaced outside the agency. That would be the first evidence against DHCF's no-misuse assessment.
  • Any revision to the 399,086 figure on the HHS breach portal once the review closes.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories