Skip to main content
Jump to a category page

LHC Group is owned by UnitedHealth Group’s Optum division and provides home health and hospice care across most of the country. The company took 150 days to tell patients that a phone-based phishing attack exposed their Social Security numbers and medical records, and it appears to be missing a separate federal breach report altogether.

LHC Group, Inc., a national home health and hospice provider acquired by UnitedHealth Group’s Optum division in 2022, has confirmed a data breach involving patient Protected Health Information. According to LHC’s notice, the company became aware on April 7, 2026 that an employee may have been the victim of a vishing, or voice phishing, attack. A third-party technology vendor that supports LHC’s referral management and care coordination systems separately reported suspicious activity tied to an LHC user account. LHC’s investigation determined that a threat actor used stolen credentials to access a large volume of files containing patient information between April 7 and April 15, 2026.

LHC began confirming the identities of affected individuals on July 9, 2026, 93 days after discovery, and issued notice to patients on or about September 4, 2026, roughly 150 days after the breach was first discovered. State filings confirm 16,885 affected Texas residents and 4,812 affected Massachusetts residents, 21,697 people across just those two states. LHC has not disclosed a national total.

A UnitedHealth Subsidiary With a Missing Federal Report

LHC Group is a HIPAA covered entity, and federal law is specific about reporting a breach of this size. Under 45 C.F.R. § 164.408(b), a covered entity must notify the U.S. Department of Health and Human Services within 60 days of discovering a breach affecting 500 or more people. On an April 7, 2026 discovery date, that deadline fell on or about June 6, 2026. As of this writing, no LHC Group entry appears in HHS’s public breach reporting portal for the relevant time period, despite LHC being a subsidiary of Optum and UnitedHealth Group, one of the largest healthcare companies in the country.

What Information Was Exposed?

LHC’s notice states that the accessed documents may have included:

  • Full names, addresses, dates of birth, and demographic information
  • Social Security numbers (in limited instances)
  • Health information such as clinical summaries, treatment plans, diagnosis codes, dates of service, and provider information
  • Health insurance information, including policy names, numbers, and plan information
  • Government identification information, such as Medicare and Medicaid ID numbers
  • Financial information (in limited instances)

LHC states that not all data elements were involved for every individual.

What Is LHC Group Offering?

LHC is offering two years of complimentary credit monitoring and identity protection services through IDX. Affected individuals can enroll at app.idx.us/account-creation/protect using the enrollment code provided in their notice letter. The enrollment deadline is December 4, 2026. Questions can be directed to 1-866-200-0905, Monday through Friday from 8:00 a.m. to 8:00 p.m. Central Time. LHC states it has no evidence that any information has been misused.

Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Healthcare providers are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.

Much of the information involved in this incident also qualifies as Protected Health Information (PHI). PHI includes medical or healthcare-related data protected under federal and state privacy laws. When PHI is compromised, it can be misused for medical identity theft or insurance fraud.

Do You Have Legal Options?

Healthcare providers have a legal duty to safeguard patient information and to report breaches of this size to federal regulators within a specific timeframe. Patients affected by this breach may have rights and remedies under applicable law, including claims tied to the 150-day delay between discovery and notice.

If you are a current or former patient of an LHC Group-affiliated home health or hospice provider and believe your information was affected, contact the Data Breach Attorneys at Emery | Reddy for a Free Case Review.

Frequently Asked Questions

How many people were affected by the LHC Group data breach?

State filings confirm 16,885 affected Texas residents and 4,812 affected Massachusetts residents, 21,697 people across just those two states. LHC Group has not disclosed a national total, though the company operates in most states.

What happened, and when?

LHC Group discovered on April 7, 2026 that an employee may have been the victim of a vishing attack. Investigators determined a threat actor used stolen credentials to access patient files between April 7 and April 15, 2026, through a third-party vendor platform. LHC began confirming affected individuals on July 9, 2026 and issued notice on or about September 4, 2026.

Is LHC Group connected to UnitedHealth Group or Optum?

Yes. LHC Group was acquired by UnitedHealth Group’s Optum division in 2022 and operates as an Optum subsidiary.

Did LHC Group meet its federal reporting deadline?

That is an open question. HIPAA requires notice to the U.S. Department of Health and Human Services within 60 days of discovering a breach of this size, which would have fallen on or about June 6, 2026. As of this writing, no corresponding entry has been located in HHS’s public breach reporting portal.

Is LHC Group offering credit monitoring?

Yes. LHC is offering two years of complimentary credit monitoring and identity protection through IDX. Enrollment is available at app.idx.us/account-creation/protect using the code in the notice letter, with a December 4, 2026 deadline.

Do I have a legal claim?

You may. Healthcare providers are required by law to protect patient information and to report breaches to federal regulators within a specific timeframe. Contact the Data Breach Attorneys at Emery | Reddy at 916.995.5968 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.

"Very friendly interview and intake process. I was informed thoroughly about the processes in obtaining a lawyer and was given ample time to make a decision on representation. I’m thankful for everyone’s help and looking forward to working with this Firm on my worker’s compensation claim."

- Darren A.

Receive a
FREE Case Review

Call Now