Were you recently affected by a data breach?

LHC Group Data Breach

LHC Group, the parent organization of many home health and hospice providers, disclosed that a threat actor stole an employee’s credentials and accessed patient files through a third-party vendor’s platform.

LHC Group
Date of Breach: April 7-15, 2026 (unauthorized access); discovered April 7, 2026
CAU logo

Who was affected:

Clients of LHC Group

Impacted Data:

Full names, addresses, dates of birth, demographic information, Social Security numbers (in limited instances), health information such as clinical summaries, treatment plans, diagnosis codes, dates of service, and physician or provider information, health insurance policy names and numbers, Medicare and Medicaid ID numbers, and financial information (in limited instances)

LHC Group, Inc., the parent organization of numerous home health and hospice care providers across the country, has disclosed a data security incident involving unauthorized access to patient information stored on a third-party technology vendor’s platform. Home healthcare organizations manage a wide range of sensitive patient records through outside vendors that support scheduling, referrals, and clinical workflows, and those organizations remain responsible for protecting that information no matter where it is technically stored.

LHC Group’s Data Breach Investigation

According to the notification letter LHC Group filed with the Massachusetts Attorney General’s office, LHC became aware on April 7, 2026 that an employee may have been the victim of a vishing, or voice phishing, attack. Shortly afterward, LHC’s third-party vendor reported suspicious activity on its platform associated with an LHC user account. LHC launched an investigation, took steps to secure its systems, worked with the vendor, enlisted third-party forensic experts, and notified the FBI.

The investigation determined that a threat actor used the stolen credentials to access a large volume of files containing patient Protected Health Information on the vendor’s platform. The unauthorized access is reported to have occurred between April 7 and April 15, 2026. After an extensive review of the accessed files, LHC began confirming the identities of impacted individuals on July 9, 2026.

Vishing attacks, in which an attacker impersonates a trusted party over the phone to trick an employee into revealing login credentials or granting system access, remain one of the more effective ways cybercriminals compromise otherwise well-secured networks, since they target human judgment rather than a technical vulnerability. Once valid credentials are obtained, an attacker can often move through a vendor’s platform with the same access as a legitimate employee, which is consistent with how LHC describes the threat actor accessing a large volume of patient files here. This incident is separate from an earlier, unrelated 2026 disclosure in which LHC Group notified patients of a different data exposure tied to a vendor called Doctor Alliance — that earlier incident affected a distinct group of individuals and should not be confused with the vishing-related access described in this notice.

Following the incident, LHC took steps to strengthen its security, including disabling the compromised account, conducting a broader security review, enhancing authentication requirements and monitoring, and strengthening additional security controls to reduce the risk of a similar incident recurring.

When Did This Breach Occur?

LHC Group states that it became aware of the vishing attack on April 7, 2026, that the unauthorized access to the vendor’s platform occurred between April 7 and April 15, 2026, and that it began confirming the identities of impacted individuals on July 9, 2026.

What Information Was Breached?

LHC Group’s notification letter states that the threat actor accessed documents that may have included full names, addresses, dates of birth, and demographic information; Social Security numbers in limited instances; health information such as clinical summaries, treatment plans, diagnosis codes, dates of service, and physician or provider information; health insurance policy names, numbers, and plan information; Medicare and Medicaid identification numbers; and financial information in limited instances. LHC states that not all data elements were involved for every individual.

What You Can Do

LHC Group is offering affected individuals two years of complimentary credit monitoring and identity protection services through IDX at no cost, with enrollment available by scanning a QR code or visiting IDX’s enrollment site using the code provided in the individual notification letter. The company states it has no evidence that any exposed information has actually been misused. It’s still worth reviewing your explanation-of-benefits statements, bank and credit card statements, and credit reports for anything unfamiliar, and reporting suspicious activity promptly.

File a Data Breach Lawsuit Against LHC Group

If you received a notice from LHC Group about this incident, keep it as documentation, since it can help establish that your information was involved if you decide to pursue legal action.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: August 10, 2026
Date of Breach: Not publicly disclosed in the firm's notice
Date of Breach: Unauthorized access discovered on or about August 17, 2026, following an extensive forensic investigation
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.