A hidden field in DC health reports exposed 400,000 Medicaid files

Two public reports on the DC health finance agency's website carried personal data in fields no visitor was meant to read.

CSBadmin
2 Min Read

Nearly 400,000 people in the District of Columbia are getting letters from the agency that runs the city’s Medicaid program, after two reports on its website turned out to expose personal details in a place no visitor could see.

The agency is the Department of Health Care Finance, known as DHCF, and it reported the exposure to the US Department of Health and Human Services as affecting 399,086 people. Everyone in the affected group signed up for Medicaid or the DC Healthcare Alliance at some point from 2023 through 2026.

Nobody hacked anything. The two reports were built for public viewing, and on the screen they showed only enrollment counts and other summary statistics. DHCF said the reports “did not show anyone’s personal details on the screen.” What sat behind them went well beyond enrollment totals, and it ran to fields such as Medicaid IDs, provider names, dates of birth, race, gender, ethnicity and ward. That detail stayed reachable to unauthorized users from 2023 until July 2026, when the agency spotted the problem.

Social Security numbers, names and financial account details were not part of the exposed set. The agency’s stated position is that it has seen nothing to suggest the information was viewed or misused, and it asks people in the affected group to stay alert for fraud.

DHCF pulled both reports as soon as it found the problem, opened an internal review and ran system checks. Late last week the incident turned up on the federal breach portal that HHS maintains.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.