Conn. (WFSB) – LHC Group, a major national provider of in-home healthcare services, is notifying patients of a recent data security breach that may have exposed private patient information
The breach occurred after an employee fell victim to a voice phishing phone call, allowing a hacker to access patient records.
LHC learned about the voice phishing attack on April 7, and suspicious activity was later detected on an LHC user account. An investigation revealed that the hacker stole login credentials to access patient files.
LHC began identifying those impacted by this data breach on July 9. The company says the data accessed may include:
- Personal Details: Names, physical addresses, dates of birth, and demographic information.
- Medical Information: Clinical summaries, treatment plans, and diagnosis codes.
- Provider & Insurance Details: Physician names, health insurance policy names, numbers, and plan details.
- Government IDs: Medicare and Medicaid ID numbers.
- Sensitive Data: Social Security numbers and financial details were accessed in a limited number of cases.
Upon discovering the suspicious activity, LHC Group says they contacted the FBI, secured their systems, and have begun sending out notification letters to potentially impacted individuals.
While LHC Group says it is currently unaware of any actual misuse or fraud resulting from this data breach, patients are strongly urged to monitor their accounts and report suspicious activity.
Copyright 2026 WFSB. All rights reserved.