LHC Group Data Breach Impacts 16k: Medical Records Compromised

Published
September 4, 2026
Updated
September 4, 2026
LHC Group Data Breach Impacts 16k: Medical Records Compromised
LHC Group
Affected by the data breach? You may be entitled to compensation. Submit a claim today.

LHC Group Inc, a national provider of in-home healthcare services, disclosed a data breach that occurred through an unnamed third-party technology vendor's platform.

According to a filing with the Texas Attorney General dated Sept. 4, 2026, the breach affected 16,885 Texas residents. The company posted a notice on its website.

LHC Group uses a third-party technology vendor to support referral management, care coordination and clinical workflow functions for its home healthcare services. On April 7, 2026, the company became aware that an employee may have been the victim of a vishing attack. Vishing, or voice phishing, is a type of social engineering in which a caller tricks someone into sharing sensitive information such as login credentials.

Shortly after the attack was identified, the vendor reported suspicious activity on its platform tied to an LHC Group user account.

The company's investigation found that a threat actor used stolen credentials to access a large volume of files on the vendor's platform containing patient protected health information. The unauthorized access continued from April 7 through April 15, 2026.

After a review and data analysis, LHC Group began confirming the identities of affected individuals on July 9, 2026.

The types of personally identifiable information (PII) exposed included full names, addresses, dates of birth, demographics and, in limited instances, Social Security numbers and financial information.

Protected health information (PHI) was also accessed, including clinical summaries, treatment plans, diagnosis codes, dates of service and physician or provider details. Health insurance information such as policy names, numbers and plan details was compromised as well, along with government identification numbers including Medicare and Medicaid IDs.

LHC Group's response to the breach

The company is offering affected individuals two years of complimentary credit monitoring and identity protection services through IDX. Individuals can enroll by visiting the IDX enrollment page and entering the enrollment code included in their notification letter. The enrollment deadline is Dec. 4, 2026.

The company encouraged affected individuals to remain vigilant by monitoring their financial accounts and health insurance statements.

LHC Group has set up a dedicated call center for anyone with questions or concerns. It can be reached toll-free at 1-866-200-0905, Monday through Friday, 8 a.m. to 8 p.m. Central Time, excluding holidays.

SUBMIT YOUR CLAIM TO THE LAW FIRM HANDLING THIS INVESTIGATION

Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info
  • Affected information types not yet disclosed

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Affected Entity
LHC Group
Consumers Notification date
Date of Breach
Breach Discovered Date
Total People Affected
Information Types Exposed
  • Name of individual
  • Address
  • Social Security Number Information
  • Medical Information
  • Health Insurance Information
  • Date of Birth
  • Full names
  • Demographics
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image