Skip to content
>_ITDITDWeb Security Platform

Security Guides

DC Medicaid data exposure (about 400,000 people): Medicaid IDs left in published reports — what members and report publishers should do

Two public DC Medicaid reports held hidden Medicaid IDs and birth dates of 399,086 people. What members should do, and what to check before publishing reports.

Published 2026-10-03 Updated 2026-10-03 Last verified 2026-10-03 9 min read

For: Medicaid and DC Healthcare Alliance beneficiaries in Washington, DC (2023 onward), and anyone at a government body or company who publishes statistical reports, spreadsheets or dashboards on the web. This article is based on the official notice from the Department of Health Care Finance (DHCF).

What members should do today

1

Check whether you received a letter from DHCF

DHCF is mailing individual letters to affected people. Those affected are Medicaid and DC Healthcare Alliance (a DC-funded health coverage program) beneficiaries.

With questions, call the toll-free line 1-833-687-5424 given in DHCF's notice. If someone calls or emails asking for your details "about the incident", hang up and call that number yourself.

2

Look for care or prescriptions you never received

The exposed data included Medicaid ID numbers and dates of birth. These are used at check-in and for coverage checks, so it is reasonable to watch for someone else using your coverage (medical identity theft).

Read the notices from your providers and health plan for visits or prescriptions you do not recognize. If you find one, call DHCF's line, and you can also report it at the Federal Trade Commission's identitytheft.gov.

3

Consider the credit checks and freezes DHCF recommends

According to the notice, names and Social Security numbers were not included. DHCF still recommends three steps:

  • Get your free credit reports at annualcreditreport.com and look for accounts you did not open
  • Place a fraud alert with the credit bureaus
  • Place a security freeze with Equifax, Experian and TransUnion

A freeze is free, and you can lift it temporarily when you apply for credit yourself.

4

Report identity theft if you see it

DHCF's notice lists the FTC, the DC Office of the Attorney General (202-727-3400) and law enforcement as places to report suspected identity theft. Do not answer messages that use the letters or news coverage as a reason to ask for your Medicaid ID or bank details.

What happened (from DHCF's notice)

DHCF is the agency that runs DC Medicaid. It posted a "Notice of Data Incident" on its website. The following comes from that notice and from reporting on its filing with HHS.

  1. 2023 to July 2026

    Period during which the two reports were on DHCF's website. They displayed only summary statistics.
  2. July 21, 2026

    DHCF learned the reports contained hidden personal data. How it learned this has not been published.
  3. After discovery

    DHCF removed the reports from its website and began a review to strengthen internal processes.
  4. September 3, 2026

    Report to the HHS Office for Civil Rights listing 399,086 people (according to HIPAA Journal). Letters mailed to affected people.
399,086
People affected (HHS filing)
2
Reports that contained hidden personal data
2023 on
Period the reports were online (until July 2026)
Not included
Names, Social Security numbers, financial accounts
What was exposed (from DHCF's notice)
Data
Medicaid ID number, date of birth, provider name, race, gender, ward, ethnicity
Not included
Beneficiary names, Social Security numbers, financial account information
Who
Medicaid and DC Healthcare Alliance beneficiaries; 399,086 people in the HHS filing
Where
In hidden fields of two reports posted on the website. The reports were designed to show summary statistics only
File format
Not published (whether Excel, PDF or a dashboard, and the report names, have not been disclosed)
Actual access
Described as accessible to people without permission. Whether anyone actually took the data has not been published
Response
Reports removed; review of internal processes begun; letters mailed to affected people
Contact
DHCF toll-free line 1-833-687-5424

What sets this case apart: no break-in, just a file the agency published itself

Most data breaches start with someone getting into a system from outside. Here, the personal data sat inside statistical reports DHCF published itself.

Checking the numbers shown on screen will not catch this kind of problem. You have to check what is inside the file.

What is still unknown

The report names and format, how DHCF found the problem, and whether anyone actually took the data had not been published as of October 3. We will update this article if more is released.

For anyone who publishes reports, spreadsheets or dashboards

Because DHCF has not said what format its reports were, this section covers the three common formats: where source data can hide behind the totals, and how to check. Government bodies and companies everywhere publish spreadsheets, and the same kind of incident has happened elsewhere.

A case from Japan: an old roster left in hidden worksheets (Okawa City)

On August 20, 2026, Okawa City in Fukuoka, Japan, said an Excel roster of community welfare volunteers it posted in December 2025 still contained hidden worksheets. Unhiding them showed the names and phone numbers of 188 volunteers appointed in 2013, 2016 and 2019. A resident's enquiry brought it to light.

The city replaced the file with a PDF, but then found that changing the PDF's URL extension to .xlsx still opened the original spreadsheet, so it deleted the file from its site system. A replaced file can stay reachable at its old address.

Where data hides in Excel

Not visible, but still in the file

  • Hidden rows, columns and worksheets (unhide them and they are back)
  • PivotTable caches (a copy of the source data; double-clicking a total brings back the source rows)
  • White text, formulas pointing at other sheets, defined names
  • Comments and document properties such as author names
  • External data connections and data models (Power Query, Power Pivot)

How to find and remove it

  • File → Info → Check for Issues → Inspect Document finds and removes hidden rows, columns, worksheets and comments
  • In PivotTable Options → Data, clear "Save source data with file" and "Enable show details"
  • Most reliable: paste values only into a new workbook

Inspect Document helps, but it does not necessarily clear everything in pivot caches or data models. Building the public file from totals alone is safer than cleaning up a workbook that once held personal data.

Steps before you publish

1

Build the public file separately from the source data

Do not publish your working file after hiding or deleting parts of it. Make a separate public file: a CSV export of only the columns you need, or a new workbook with values pasted in. Source rows and hidden sheets never get into it.

As Okawa City decided in its prevention measures, publishing as PDF or HTML is one option. Even in a PDF, though, a black box drawn over text can leave the text underneath copyable. Use your PDF editor's redaction feature.

2

Suppress cells with small counts

Even a table of totals can identify a person when a cell holds one or two people for a given ward, age and gender. The US Centers for Medicare & Medicaid Services (CMS) has a policy of not publishing cells of 1 to 10 people. Before publishing, replace small counts with something like "fewer than 11".

3

Connect public dashboards to aggregated data only

With dashboard tools such as Power BI or Tableau, the screen may show a chart while the whole underlying dataset is sent to the browser, or can be pulled out through "show data" or "download" features. Filtering data out of view is not the same as removing it.

Connect public dashboards only to an aggregated dataset with no per-person rows, and turn off data download if you do not need it. Power BI's "Publish to web" makes a report viewable by anyone with the link.

4

Open the file the way an outsider would

Right after publishing, download the file in a browser where you are not signed in and open it as an outsider would. For a spreadsheet, unhide all sheets and run Inspect Document; for a dashboard, use the browser's developer tools (Network tab) to see what data actually arrives.

Having someone other than the author do this check makes it easier to spot what the author missed.

5

Review published files regularly

DHCF's reports stayed online for close to three years, from 2023. Keep a list of files on your website and recheck their contents at least once a year. When you replace or delete a file, confirm that the old file no longer opens at its old URL.

The best fix is not to bring per-person data into a public report in the first place. Handling only the columns and level of detail you need is what the EU's GDPR calls "data minimisation" (What is GDPR?). For data made public through sharing settings, see public cloud storage exposure; for files left in public folders, see secrets in public directories.

Sources (public record)

The facts in this article come from the following public sources. We have not guessed at the file format or how the problem was found.

  • District of Columbia Department of Health Care Finance (DHCF), "Notice of Data Incident" — dhcf.dc.gov
  • HIPAA Journal (number of people and date of the HHS Office for Civil Rights filing) — hipaajournal.com
  • Okawa City, notice on a possible personal data leak from the city website (August 20, 2026, Japanese) — city.okawa.lg.jp

Update history

2026-10-03: First version, based on DHCF's notice and reporting on its HHS filing. We will update it if the report format or further findings are published.

FAQ

QWhat was exposed in the DC Medicaid incident?
A

According to the Department of Health Care Finance (DHCF) notice, two reports on its website contained Medicaid ID numbers, dates of birth, provider names, race, gender, ward and ethnicity in a form that people without permission could access. DHCF says beneficiary names, Social Security numbers and financial account information were not included.

QHow many people are affected?
A

The DHCF notice does not give a number. The report filed with the HHS Office for Civil Rights on September 3, 2026 lists 399,086 people, according to HIPAA Journal. Those affected are Medicaid and DC Healthcare Alliance beneficiaries.

QWhat kind of file was it? Excel?
A

As of October 3, 2026, DHCF has not said what format the reports were (Excel, PDF, a dashboard or something else) or named them. The notice says the reports were designed to show only summary statistics, but the personal data behind them was contained in hidden fields.

QDid anyone actually take the data?
A

The notice says the data could be accessed by people without permission. It does not say whether there is any record of the data actually being taken.

QWhat should I do?
A

DHCF is mailing letters to affected people. If you receive one, check notices from your providers and health plan for care or prescriptions you never received. DHCF also points to free credit reports, fraud alerts and security freezes. Its toll-free line for questions is 1-833-687-5424.

QHas this happened elsewhere?
A

Yes. In August 2026, Okawa City in Fukuoka, Japan, said an Excel roster on its website still contained hidden worksheets; unhiding them showed the names and phone numbers of 188 past community welfare volunteers.