LHC GROUP, INC.
bd_ac420531928d5c01 · schema v1 · pii pii-v2
Full breach record for LHC GROUP, INC. →2 incidents on fileLHC Group, Inc. notified patients of a data breach involving a third-party vendor. On April 7, 2026, LHC became aware of a vishing attack against an employee, leading to credential theft. A threat actor accessed patient PHI from the vendor's platform between April 7 and April 15, 2026. Affected data included names, addresses, dates of birth, SSNs (limited), clinical summaries, treatment plans, diagnosis codes, and insurance information. LHC engaged forensic experts, notified the FBI, disabled the compromised account, and is offering two years of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 7, 2026
Begins
Apr 7, 2026
Discovered
Sep 1, 2026
Filed
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Washington State AGbd_2e445e42721957f72026-09-04 · +3dVerified
- Texas State AGbd_a6036561090a80a62026-09-04 · +3dCandidate
Filing propagation · 3 filings · 3 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.