Voice phishing at a vendor opens patient files at LHC Group

An April vishing call at a care-coordination vendor gave an intruder eight days of access to the home health provider's patient files.

MedRisk Staff
By
2 Min Read

For eight days in April, an intruder sat inside a vendor platform that held the patient files of a home health and hospice operator spanning 28 states. The company behind it, Lafayette, Louisiana-based LHC Group, disclosed the incident this week.

An employee appears to have handed over credentials to a caller, which let the attacker pivot into the vendor’s platform under an LHC user account. That platform was not peripheral. It carried referral traffic, care coordination, and clinical workflows, the kind of plumbing that routinely touches protected health information. The access ran from April 7 to April 15, and by the end of that stretch a substantial set of records had been taken.

What leaked varied by patient: contact details, birth dates, clinical summaries, treatment plans, diagnosis codes, service dates, physician information, Medicare and Medicaid numbers, and insurance details, with Social Security numbers or financial data in limited cases. Identity confirmation started July 9. State attorney general filings push the count past 28,000, though the real total is probably higher because several states never publish one. Doctor Alliance, another vendor, exposed LHC Group data earlier in 2026, so this is the company’s second notice of the year.

Two smaller disclosures landed alongside it. Elixir Medical Corporation, a Milpitas, California maker of heart and vascular devices, found an intruder in parts of its network on July 20 and 21 and said human resources files were taken, covering names, Social Security numbers, and in some cases driver’s license, payment card, medical, or bank details. Central Arkansas Pediatrics in Conway told 1,500 patients about a hacking incident, and the Gentlemen ransomware crew listed the practice in June.

Share This Article