Two reports that the District of Columbia’s Medicaid agency published for public viewing also carried beneficiary records underneath, and that layer stayed open to outsiders for about three years.
The agency behind the letters is the Department of Health Care Finance, which the city knows as DHCF, and it is writing to nearly 400,000 people. DHCF’s own accounting to the federal government put the tally at 399,086.
The group in scope is anyone who signed up for Medicaid or the DC Healthcare Alliance at some point from 2023 through 2026.
What could be pulled from those reports went well past enrollment totals: Medicaid identification numbers, provider names, dates of birth, race, gender, ethnicity and ward. Social Security numbers, names and financial details were not part of what was exposed.
The letters note that whatever might have been reached “did not include Social Security numbers or financial account information,” a point DHCF returns to more than once. The agency’s own stated conclusion, spelled out in the notification letters sent to every affected household, is that it is “less likely that the information connected to you, your child, or your family member will be used in the wrong way.”
The case is a reminder that a reporting layer can expose far more than the view it presents. Health systems that publish enrollment or quality portals have reason to audit what sits beneath the page, not only the figures that render.