LHC Group Data Breach Investigation
LHC Group, Inc. reported a data security incident involving credentials used to access patient files on a third-party technology platform. The files may have contained personal, health, insurance, government identification, and limited financial information. Strauss Borrelli PLLC is investigating the LHC Group data incident on behalf of potentially affected individuals. If you received a notice, you may fill out the secure contact form on this page to ask whether you may qualify to pursue a claim.
According to its consumer notice, LHC Group is a national provider of home health and hospice healthcare services. The reported incident may have affected information concerning some current and former patients.
Key Facts at a Glance
- Entity Involved: LHC Group, Inc (Healthcare)
- Incident Type: Vishing (voice phishing) attack involving stolen credentials and unauthorized access to a third-party vendor platform
- Date of Incident: April 7, 2026, to April 15, 2026
- Discovery Date: April 7, 2026
- Official Notice Date: Not stated in the available notice; a public listing was reported on September 4, 2026
- Exposed Information: Names, contact details, dates of birth, Social Security numbers, medical records, health insurance information, government identification information, and limited financial information
- Affected Population: 162,578 individuals, as reported in regulatory information
What Happened?
According to LHC Group’s official consumer notice, LHC became aware on April 7, 2026, that an employee may have been targeted in a vishing, or voice-phishing, attack. The notice states that an unnamed third-party technology vendor then identified suspicious activity tied to an LHC user account on its platform, which supported referral management, care coordination, and clinical workflows. LHC reported that it disabled the compromised account, worked with the vendor, engaged forensic specialists, and notified the FBI. Its investigation reportedly found that stolen credentials were used to access a large volume of files containing patient protected health information. The notice identifies the unauthorized access period as April 7 through April 15, 2026. LHC said it began confirming affected identities on July 9, 2026, after data review and analysis. It also stated that it had no evidence or reason to believe the information had been misused at the time of notice.
What Information Was Exposed?
LHC Group reported that the accessed documents may have contained names, addresses, dates of birth, demographic details, and patient health information. Health data may have included clinical summaries, treatment plans, diagnosis codes, dates of service, and provider information. The documents also may have included health insurance policy details, Medicare or Medicaid identification numbers, Social Security numbers in limited instances, and limited financial information. Not every affected person necessarily had every data element involved. Because healthcare information can be used in medical identity theft, individuals should watch for fraudulent patient bills, unfamiliar insurance claims, prescription inquiries, and callers seeking to “verify” insurance or treatment details.
What Should You Do Next?
- Review the notice and enroll in available protection: LHC Group reported that eligible individuals are being offered two years of complimentary IDX credit monitoring and identity protection. Follow the directions and enrollment code in your individual letter, if applicable.
- Check healthcare records and insurance statements: Review explanations of benefits, patient portal activity, medical bills, prescription histories, and insurance claims for care you did not receive. Report unexplained entries to the provider and health plan promptly.
- Monitor your credit reports: Obtain reports through AnnualCreditReport.com and look for unfamiliar accounts, inquiries, addresses, or other inaccurate information. Consider a fraud alert or credit freeze if your Social Security number may have been involved.
- Be cautious of healthcare impersonation scams: Do not provide passwords, verification codes, insurance numbers, or payment information to unexpected callers, texts, or emails claiming to represent a provider, pharmacy, insurer, or incident-response service.
- Document suspicious activity: Save your notice, enrollment confirmation, bills, correspondence, credit reports, and records of time or expenses associated with responding to the incident. Report suspected identity theft through IdentityTheft.gov and contact the appropriate insurer, provider, or financial institution.
Your Legal Rights
People whose personal or protected health information may have been involved in a data incident can have rights under federal and state privacy, consumer-protection, and data-breach laws. The specific rights and possible remedies depend on where a person lives, the information involved, applicable notice requirements, and whether the incident caused losses or other harm. Potentially affected individuals may wish to preserve their notice and records of fraudulent charges, medical identity issues, credit-monitoring costs, time spent responding, and related communications. Legal deadlines can apply, so waiting may affect available options. This general information is not individualized legal advice, and receiving a notice does not automatically establish that a person has a legal claim.
Why Hire Strauss Borrelli PLLC?
The firm’s privacy and data security attorneys can review the reported incident, the information potentially involved, and the legal protections that may apply to an affected individual. A legal review can also help determine whether further action may be appropriate based on the notice received, documented losses, and applicable law. Individuals who believe they were affected may use the secure contact form on this page to request an evaluation.
If you received a breach notification letter from LHC Group, Inc.:
We would like to speak with you about your rights and potential legal remedies in response to this data breach. Please fill out the form, below, or contact us at 872.263.1100 or sam@straussborrelli.com.










