A voice phishing call on April 7 handed intruders a home health giant’s credentials, and the attackers spent the next eight days pulling patient files from a third-party care coordination platform, according to a September 4 filing with the Texas attorney general.
One of the largest US home health operators, LHC Group, said an employee surrendered account credentials during the vishing call and the vendor behind the breached platform flagged suspicious activity tied to the company’s account almost immediately. The platform is used to manage referrals, coordinate care, and move clinical work through the company’s agencies. Investigators later determined the intruders reached records containing protected health information between April 7 and April 15.
The exposed material spans clinical summaries, treatment plans, diagnosis codes, dates of service, provider details, and health insurance policy data, along with Medicare and Medicaid identifiers. A limited number of Social Security numbers and financial records were also involved, LHC Group said.
The Texas filing lists 16,885 affected residents, and notification letters are reaching patients in other states, including East Tennessee, where local media reported the disclosure this week. LHC Group is offering two years of credit monitoring and identity protection through IDX, with enrollment open until December 4, and has set up a dedicated call center for affected individuals.
The episode echoes the surge in vishing that health sector warnings have flagged all year, as voice scams overtake email as a favored entry point into clinical networks. LHC Group began matching records to specific individuals on July 9, months before the first public notice appeared.