The District of Columbia Department of Health Care Finance is notifying nearly 400,000 Medicaid and DC Healthcare Alliance beneficiaries after discovering that two reports on its public website contained hidden personal information. The incident was not described as a network intrusion; the exposure came from underlying report data that unauthorized users could potentially reach.
Summary reports contained accessible supporting records
The reports were intended to display enrollment totals and other aggregate statistics. DHCF said the visible pages did not show personal details, but supporting information may have been accessible between 2023 and July 2026. The affected population includes beneficiaries enrolled during that period.
The exposed fields varied by record and included Medicaid identifiers and other personal information. DHCF removed the reports, investigated the issue and began notifying affected people. The agency’s notice provides current details and assistance information.
Publication workflows need hidden-data testing
Organizations publishing dashboards, spreadsheets or generated reports should inspect source files, embedded datasets, metadata and export endpoints before release. Access tests must verify what an unauthenticated user can retrieve, not only what the page displays. SectechMedia follows related controls in its cybersecurity coverage.

Leave a Reply