DC DHCF Exposes 399,086 Medicaid Records via Hidden Fields in Public Web Reports
A three-year misconfiguration in DC health agency web reports exposed limited PII for nearly 400,000 beneficiaries without evidence of malicious access. The case highlights persistent sanitization failures in government Medicaid portals and the gap between official claims of low risk and actual exposure duration.
The exposure occurred when DHCF posted aggregate enrollment reports that retained underlying PII in HTML source or attached data structures. No intrusion or external actor was involved; the reports simply failed to sanitize fields intended only for internal aggregation. The agency notified HHS on the breach affecting Medicaid and DC Healthcare Alliance enrollees and removed the files immediately after discovery.
Procurement and incident records show repeated web misconfigurations in DC health systems, including prior portal exposures where summary dashboards leaked identifiers. This pattern aligns with broader state Medicaid IT deployments that prioritize rapid public reporting over field-level access controls. Absence of SSNs and financial data lowers direct fraud utility but still enables targeted profiling by ward and ethnicity.
Independent verification via the HHS breach portal confirms the 399,086 figure. No forensic logs indicate access attempts, yet the three-year window leaves open the possibility of undetected scraping by automated crawlers. Future reviews must examine all public-facing dashboards rather than isolated reports.
DHCF has begun internal audits and system checks. Expect expanded scans of legacy reporting tools and possible additional notifications if further unsanitized datasets surface before year-end.
DHCF: Internal review will identify at least one additional exposed dataset containing beneficiary PII before December 2026.
Sources (2)
- [1]Primary Source(https://www.securityweek.com/dc-health-agency-exposes-400000-beneficiary-records/)
- [2]Supporting Source(https://ocrportal.hhs.gov/ocr/breach/wizard_breach.jsf)