LHC Group, Inc. disclosed a data breach that may have exposed patients’ and employees’ personal and health information, including Social Security numbers and medical details. The company notified the Washington State Attorney General in September 2026. Affected individuals should watch for an official notification letter and place a credit freeze or fraud alert immediately to reduce identity theft risk.
| Company | LHC Group, Inc. |
|---|---|
| Industry | Healthcare |
| Data Types Exposed | Full Names, Social Security Numbers, Dates of Birth, Medical Treatment Information, Health Insurance Information, Patient Account Numbers |
| People Affected | Not Publicly Disclosed |
| Attack Method | Unspecified/Unauthorized Access |
| Regulators Notified | Washington State Attorney General |
Were you affected by this breach?
You may be owed compensation.
Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.
Check if you qualify — free reviewWhat Happened in the LHC Group Data Breach?
LHC Group, Inc. recently disclosed a data breach that may have compromised sensitive personal information belonging to patients, employees, or other individuals connected to its home health and hospice services. The company filed a formal notification about the incident with the Washington State Attorney General in September 2026. This filing confirmed that unauthorized parties may have accessed protected data held within LHC Group’s systems.
The exact date that the breach was discovered has not been publicly disclosed. However, the notification filed with regulators indicates that LHC Group identified suspicious activity affecting its network and moved to investigate further. As a result, the company began working to determine which systems were involved and what types of information may have been exposed.
Following discovery of the incident, LHC Group engaged in a forensic review to assess the scope of the breach. This process typically involves determining how attackers gained access, which files or databases were touched, and whether data was actually copied or stolen. Because these investigations take time, full details about the intrusion method have not yet been made public.
In addition, LHC Group appears to have taken steps to secure its network once the breach was confirmed. This is a standard part of incident response for healthcare-related organizations facing this kind of exposure. Meanwhile, affected individuals are only now learning the details through breach notification letters and regulatory filings.
Who was affected?
The population affected by the LHC Group data breach likely includes patients who received home health, hospice, or related care services through the organization. It may also include employees whose personnel records were stored on the compromised systems. Because LHC Group operates across multiple states, the geographic scope of affected individuals could be broad.
The exact number of people affected has not been publicly disclosed. Therefore, individuals who interacted with LHC Group’s services or worked for the company should watch for an official notification letter. This letter would confirm whether their specific information was involved in the incident.
Given the nature of home health and hospice care, older adults and medically vulnerable patients may make up a significant portion of those affected. In addition, family members or caregivers listed in patient records could also be impacted. This raises particular concern, since these populations are often targeted by scammers seeking to exploit sensitive health situations.
What Information Was Potentially Exposed?
While the full scope of compromised data has not been detailed publicly, breach notifications of this kind for healthcare providers commonly involve a range of sensitive personal and medical information. Based on the nature of LHC Group’s services and the type of filing made, the following categories of information may have been involved.
- Full names
- Social Security numbers
- Dates of birth
- Medical treatment or diagnosis information
- Health insurance information
- Patient account or medical record numbers
If Social Security numbers were exposed, affected individuals face a heightened risk of identity theft. Criminals can use this information to open new credit accounts, file fraudulent tax returns, or apply for loans in someone else’s name. This type of fraud can be difficult to detect immediately and may take months to unwind.
Similarly, exposure of medical or health insurance information creates risk of medical identity theft. This occurs when someone uses stolen health data to receive treatment, obtain prescriptions, or submit fraudulent insurance claims. As a result, victims may find inaccurate information in their own medical records, which can affect future care and insurance coverage.
What is the company doing?
In response to the breach, LHC Group took steps to investigate the incident and confirm which data may have been compromised. The company also filed formal notification with the Washington State Attorney General, as required under state breach notification laws. This filing allows regulators to track the incident and ensures affected residents receive proper notice.
Specifically, LHC Group filed notice with the Washington State Attorney General on September 8, 2026. This filing is part of the company’s broader legal obligation to notify state regulators and affected individuals about the exposure. Going forward, LHC Group is expected to continue notifying impacted individuals directly and may offer additional protective resources as part of its response.
Beyond notification, organizations facing breaches like this one often review and strengthen their internal security controls. This may include updating access permissions, monitoring for further suspicious activity, and working with cybersecurity specialists. These steps aim to reduce the likelihood of a similar incident happening again.
What Should Affected Individuals Do?
Monitor Your Credit Reports
Affected individuals should begin monitoring their credit reports closely for any unfamiliar activity. This includes checking for new accounts, unexpected credit inquiries, or unfamiliar charges. Early detection can help limit the financial damage caused by identity theft.
You can request free copies of your credit report from each of the three major credit bureaus. Because fraud can appear months after a breach, it helps to check your reports periodically rather than just once. If you notice anything suspicious, report it to the credit bureau immediately.
Consider a Fraud Alert or Credit Freeze
Since Social Security numbers may have been exposed, placing a fraud alert or credit freeze is a strong protective step. A fraud alert requires lenders to verify your identity before opening new credit in your name. A credit freeze goes further by restricting access to your credit file entirely.
To set up either option, contact one of the three major credit bureaus directly. That bureau is required to notify the other two on your behalf. This process is free and can be lifted temporarily whenever you need to apply for credit yourself.
Protect Against Medical Identity Theft
Because health-related information may have been involved, it’s important to review any medical statements or insurance explanations of benefits you receive. Look for services or treatments you don’t recognize. This could indicate that someone else used your identity to receive care.
If you spot anything unusual, contact your healthcare provider or insurance company right away. In addition, request a copy of your medical records to check for inaccuracies. Correcting fraudulent entries early can prevent complications with future treatment or insurance claims.
Stay Alert to Phishing Attempts
After a data breach, scammers often use exposed information to craft convincing phishing emails, texts, or phone calls. These messages may pretend to be from LHC Group, a healthcare provider, or a government agency. Because these scams can look legitimate, caution is essential.
Never click links or share personal details in response to unexpected messages. Instead, verify requests by contacting the organization directly using a known phone number or website. If something feels urgent or too good to be true, it’s likely a scam attempt.
Consult a Data Breach Attorney
If you received a notification letter from LHC Group, you may want to speak with an attorney who focuses on data breach cases. They can help you understand your legal options and whether you qualify for compensation. Many offer free consultations to evaluate your situation.
In addition, an attorney can help you determine filing deadlines that may apply to your case. Because these deadlines vary by state and case type, professional guidance can help protect your rights before time runs out.
Get a Free Case Review
Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.
More Information
Official data breach notification report (PDF) from Washington State Attorney General
