LHC Group, Inc., the parent organization of numerous home health and hospice care providers across the country, has disclosed a data security incident involving unauthorized access to patient information stored on a third-party technology vendor’s platform. Home healthcare organizations manage a wide range of sensitive patient records through outside vendors that support scheduling, referrals, and clinical workflows, and those organizations remain responsible for protecting that information no matter where it is technically stored.
LHC Group’s Data Breach Investigation
According to the notification letter LHC Group filed with the Massachusetts Attorney General’s office, LHC became aware on April 7, 2026 that an employee may have been the victim of a vishing, or voice phishing, attack. Shortly afterward, LHC’s third-party vendor reported suspicious activity on its platform associated with an LHC user account. LHC launched an investigation, took steps to secure its systems, worked with the vendor, enlisted third-party forensic experts, and notified the FBI.
The investigation determined that a threat actor used the stolen credentials to access a large volume of files containing patient Protected Health Information on the vendor’s platform. The unauthorized access is reported to have occurred between April 7 and April 15, 2026. After an extensive review of the accessed files, LHC began confirming the identities of impacted individuals on July 9, 2026.
Vishing attacks, in which an attacker impersonates a trusted party over the phone to trick an employee into revealing login credentials or granting system access, remain one of the more effective ways cybercriminals compromise otherwise well-secured networks, since they target human judgment rather than a technical vulnerability. Once valid credentials are obtained, an attacker can often move through a vendor’s platform with the same access as a legitimate employee, which is consistent with how LHC describes the threat actor accessing a large volume of patient files here. This incident is separate from an earlier, unrelated 2026 disclosure in which LHC Group notified patients of a different data exposure tied to a vendor called Doctor Alliance — that earlier incident affected a distinct group of individuals and should not be confused with the vishing-related access described in this notice.
Following the incident, LHC took steps to strengthen its security, including disabling the compromised account, conducting a broader security review, enhancing authentication requirements and monitoring, and strengthening additional security controls to reduce the risk of a similar incident recurring.
When Did This Breach Occur?
LHC Group states that it became aware of the vishing attack on April 7, 2026, that the unauthorized access to the vendor’s platform occurred between April 7 and April 15, 2026, and that it began confirming the identities of impacted individuals on July 9, 2026.
What Information Was Breached?
LHC Group’s notification letter states that the threat actor accessed documents that may have included full names, addresses, dates of birth, and demographic information; Social Security numbers in limited instances; health information such as clinical summaries, treatment plans, diagnosis codes, dates of service, and physician or provider information; health insurance policy names, numbers, and plan information; Medicare and Medicaid identification numbers; and financial information in limited instances. LHC states that not all data elements were involved for every individual.
What You Can Do
LHC Group is offering affected individuals two years of complimentary credit monitoring and identity protection services through IDX at no cost, with enrollment available by scanning a QR code or visiting IDX’s enrollment site using the code provided in the individual notification letter. The company states it has no evidence that any exposed information has actually been misused. It’s still worth reviewing your explanation-of-benefits statements, bank and credit card statements, and credit reports for anything unfamiliar, and reporting suspicious activity promptly.
File a Data Breach Lawsuit Against LHC Group
If you received a notice from LHC Group about this incident, keep it as documentation, since it can help establish that your information was involved if you decide to pursue legal action.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.