Security Guides
DC Medicaid data exposure (about 400,000 people): Medicaid IDs left in published reports — what members and report publishers should do
Two public DC Medicaid reports held hidden Medicaid IDs and birth dates of 399,086 people. What members should do, and what to check before publishing reports.
For: Medicaid and DC Healthcare Alliance beneficiaries in Washington, DC (2023 onward), and anyone at a government body or company who publishes statistical reports, spreadsheets or dashboards on the web. This article is based on the official notice from the Department of Health Care Finance (DHCF).
What members should do today
Check whether you received a letter from DHCF
DHCF is mailing individual letters to affected people. Those affected are Medicaid and DC Healthcare Alliance (a DC-funded health coverage program) beneficiaries.
With questions, call the toll-free line 1-833-687-5424 given in DHCF's notice. If someone calls or emails asking for your details "about the incident", hang up and call that number yourself.
Look for care or prescriptions you never received
The exposed data included Medicaid ID numbers and dates of birth. These are used at check-in and for coverage checks, so it is reasonable to watch for someone else using your coverage (medical identity theft).
Read the notices from your providers and health plan for visits or prescriptions you do not recognize. If you find one, call DHCF's line, and you can also report it at the Federal Trade Commission's identitytheft.gov.
Consider the credit checks and freezes DHCF recommends
According to the notice, names and Social Security numbers were not included. DHCF still recommends three steps:
- Get your free credit reports at annualcreditreport.com and look for accounts you did not open
- Place a fraud alert with the credit bureaus
- Place a security freeze with Equifax, Experian and TransUnion
A freeze is free, and you can lift it temporarily when you apply for credit yourself.
Report identity theft if you see it
DHCF's notice lists the FTC, the DC Office of the Attorney General (202-727-3400) and law enforcement as places to report suspected identity theft. Do not answer messages that use the letters or news coverage as a reason to ask for your Medicaid ID or bank details.
What happened (from DHCF's notice)
DHCF is the agency that runs DC Medicaid. It posted a "Notice of Data Incident" on its website. The following comes from that notice and from reporting on its filing with HHS.
2023 to July 2026
Period during which the two reports were on DHCF's website. They displayed only summary statistics.July 21, 2026
DHCF learned the reports contained hidden personal data. How it learned this has not been published.After discovery
DHCF removed the reports from its website and began a review to strengthen internal processes.September 3, 2026
Report to the HHS Office for Civil Rights listing 399,086 people (according to HIPAA Journal). Letters mailed to affected people.
- Data
- Medicaid ID number, date of birth, provider name, race, gender, ward, ethnicity
- Not included
- Beneficiary names, Social Security numbers, financial account information
- Who
- Medicaid and DC Healthcare Alliance beneficiaries; 399,086 people in the HHS filing
- Where
- In hidden fields of two reports posted on the website. The reports were designed to show summary statistics only
- File format
- Not published (whether Excel, PDF or a dashboard, and the report names, have not been disclosed)
- Actual access
- Described as accessible to people without permission. Whether anyone actually took the data has not been published
- Response
- Reports removed; review of internal processes begun; letters mailed to affected people
- Contact
- DHCF toll-free line 1-833-687-5424
What sets this case apart: no break-in, just a file the agency published itself
Most data breaches start with someone getting into a system from outside. Here, the personal data sat inside statistical reports DHCF published itself.
Checking the numbers shown on screen will not catch this kind of problem. You have to check what is inside the file.
What is still unknown
The report names and format, how DHCF found the problem, and whether anyone actually took the data had not been published as of October 3. We will update this article if more is released.
For anyone who publishes reports, spreadsheets or dashboards
Because DHCF has not said what format its reports were, this section covers the three common formats: where source data can hide behind the totals, and how to check. Government bodies and companies everywhere publish spreadsheets, and the same kind of incident has happened elsewhere.
A case from Japan: an old roster left in hidden worksheets (Okawa City)
On August 20, 2026, Okawa City in Fukuoka, Japan, said an Excel roster of community welfare volunteers it posted in December 2025 still contained hidden worksheets. Unhiding them showed the names and phone numbers of 188 volunteers appointed in 2013, 2016 and 2019. A resident's enquiry brought it to light.
The city replaced the file with a PDF, but then found that changing the PDF's URL extension to .xlsx still opened the original spreadsheet, so it deleted the file from its site system. A replaced file can stay reachable at its old address.
Where data hides in Excel
Not visible, but still in the file
- Hidden rows, columns and worksheets (unhide them and they are back)
- PivotTable caches (a copy of the source data; double-clicking a total brings back the source rows)
- White text, formulas pointing at other sheets, defined names
- Comments and document properties such as author names
- External data connections and data models (Power Query, Power Pivot)
How to find and remove it
- File → Info → Check for Issues → Inspect Document finds and removes hidden rows, columns, worksheets and comments
- In PivotTable Options → Data, clear "Save source data with file" and "Enable show details"
- Most reliable: paste values only into a new workbook
Inspect Document helps, but it does not necessarily clear everything in pivot caches or data models. Building the public file from totals alone is safer than cleaning up a workbook that once held personal data.
Steps before you publish
Build the public file separately from the source data
Do not publish your working file after hiding or deleting parts of it. Make a separate public file: a CSV export of only the columns you need, or a new workbook with values pasted in. Source rows and hidden sheets never get into it.
As Okawa City decided in its prevention measures, publishing as PDF or HTML is one option. Even in a PDF, though, a black box drawn over text can leave the text underneath copyable. Use your PDF editor's redaction feature.
Suppress cells with small counts
Even a table of totals can identify a person when a cell holds one or two people for a given ward, age and gender. The US Centers for Medicare & Medicaid Services (CMS) has a policy of not publishing cells of 1 to 10 people. Before publishing, replace small counts with something like "fewer than 11".
Connect public dashboards to aggregated data only
With dashboard tools such as Power BI or Tableau, the screen may show a chart while the whole underlying dataset is sent to the browser, or can be pulled out through "show data" or "download" features. Filtering data out of view is not the same as removing it.
Connect public dashboards only to an aggregated dataset with no per-person rows, and turn off data download if you do not need it. Power BI's "Publish to web" makes a report viewable by anyone with the link.
Open the file the way an outsider would
Right after publishing, download the file in a browser where you are not signed in and open it as an outsider would. For a spreadsheet, unhide all sheets and run Inspect Document; for a dashboard, use the browser's developer tools (Network tab) to see what data actually arrives.
Having someone other than the author do this check makes it easier to spot what the author missed.
Review published files regularly
DHCF's reports stayed online for close to three years, from 2023. Keep a list of files on your website and recheck their contents at least once a year. When you replace or delete a file, confirm that the old file no longer opens at its old URL.
The best fix is not to bring per-person data into a public report in the first place. Handling only the columns and level of detail you need is what the EU's GDPR calls "data minimisation" (What is GDPR?). For data made public through sharing settings, see public cloud storage exposure; for files left in public folders, see secrets in public directories.
Sources (public record)
The facts in this article come from the following public sources. We have not guessed at the file format or how the problem was found.
- District of Columbia Department of Health Care Finance (DHCF), "Notice of Data Incident" — dhcf.dc.gov
- HIPAA Journal (number of people and date of the HHS Office for Civil Rights filing) — hipaajournal.com
- Okawa City, notice on a possible personal data leak from the city website (August 20, 2026, Japanese) — city.okawa.lg.jp
Update history
2026-10-03: First version, based on DHCF's notice and reporting on its HHS filing. We will update it if the report format or further findings are published.
Read next
- US healthcare incidents: US healthcare data breaches (2026)
- Government incidents: Government data breaches (2026) / Texas Parks and Wildlife Department
- Exposure through settings: Public cloud storage exposure / Secrets in public directories
- Other 2026 incidents: list of breaches and cyberattacks (Japan and worldwide)
FAQ
QWhat was exposed in the DC Medicaid incident?
According to the Department of Health Care Finance (DHCF) notice, two reports on its website contained Medicaid ID numbers, dates of birth, provider names, race, gender, ward and ethnicity in a form that people without permission could access. DHCF says beneficiary names, Social Security numbers and financial account information were not included.
QHow many people are affected?
The DHCF notice does not give a number. The report filed with the HHS Office for Civil Rights on September 3, 2026 lists 399,086 people, according to HIPAA Journal. Those affected are Medicaid and DC Healthcare Alliance beneficiaries.
QWhat kind of file was it? Excel?
As of October 3, 2026, DHCF has not said what format the reports were (Excel, PDF, a dashboard or something else) or named them. The notice says the reports were designed to show only summary statistics, but the personal data behind them was contained in hidden fields.
QDid anyone actually take the data?
The notice says the data could be accessed by people without permission. It does not say whether there is any record of the data actually being taken.
QWhat should I do?
DHCF is mailing letters to affected people. If you receive one, check notices from your providers and health plan for care or prescriptions you never received. DHCF also points to free credit reports, fraud alerts and security freezes. Its toll-free line for questions is 1-833-687-5424.
QHas this happened elsewhere?
Yes. In August 2026, Okawa City in Fukuoka, Japan, said an Excel roster on its website still contained hidden worksheets; unhiding them showed the names and phone numbers of 188 past community welfare volunteers.