LHC Group Data Breach Investigation — Do You Qualify?
Updated September 5, 2026
- Defendant
- LHC Group, Inc.
- Status
- Under investigation
- Potential compensation
- If the case succeeds or settles
- How to join
- Accepting claimants now
- Proof required
- No claim form proof for basic payout
Overview
- Provider role
- National home health and hospice company using a vendor platform for patient workflows
- Access period
- April 7–15, 2026, according to LHC's official notice
- Records involved
- Personal, clinical, insurance, government-ID, and limited financial data varied by person
- Available now
- Notified people can enroll in two years of IDX protection by December 4, 2026
LHC Group, Inc. is a national provider of home health and hospice services. Patients may encounter LHC through clinicians who visit a home, hospice care, referrals from hospitals or physicians, and care-coordination services. LHC says it uses a third-party technology vendor for referral management, care coordination, and clinical workflows. That vendor platform is central to this incident because it held files containing patient information.
According to LHC's September 3, 2026 substitute notice, the company learned on April 7 that an employee may have been deceived in a vishing attack. Vishing is voice phishing: a caller or voice message attempts to trick someone into disclosing credentials or taking another security-sensitive action. The vendor then reported suspicious activity tied to an LHC user account.
LHC says a threat actor used stolen credentials to access a large volume of files on the vendor platform from April 7 through April 15. The files contained patient personal information and protected health information. Depending on the individual, the material may have included names, addresses, birth dates, demographic information, clinical summaries, treatment plans, diagnosis codes, dates of service, provider details, insurance information, Medicare or Medicaid identifiers, and, in limited instances, Social Security numbers or financial information.
LHC says it disabled the compromised account, investigated with the vendor and forensic specialists, notified the FBI, and strengthened authentication, monitoring, and other security controls. It is offering notified individuals two years of IDX credit monitoring and identity protection, with a December 4, 2026 enrollment deadline. Attorneys are separately recruiting affected people to evaluate possible claims. No filed complaint, certified class, settlement fund, or guaranteed payment was verified for this investigation.
Who qualifies
- You are a current or former LHC Group patient and received a notice saying your information may have been in the files accessed through the vendor platform.
- You received home health, hospice, referral, care-coordination, or related services from an LHC Group operation and want LHC to clarify whether your records were involved.
- Your notice identifies personal information, protected health information, insurance information, a Medicare or Medicaid identifier, a Social Security number, or financial information as potentially affected.
- You understand that the active attorney intake is not a court-approved settlement claim and that any future case may define the covered group differently.
How to file your claim
- 1Keep the complete LHC incident notice, envelope, enrollment code, and records showing your relationship with an LHC Group provider.
- 2If you received a valid enrollment code, follow the official notice to activate the two years of IDX credit monitoring and identity protection by December 4, 2026. The service must be activated to operate.
- 3Review healthcare explanation-of-benefits statements, bills, insurance records, credit reports, financial accounts, and tax records for unfamiliar activity. Report errors through the relevant insurer, provider, bureau, or financial institution.
- 4Preserve receipts, correspondence, fraud reports, replacement-document costs, medical-identity corrections, and time spent responding to the incident.
- 5Submit the eligibility form below only if you want a lawyer or legal representative to evaluate possible claims. It is not an official settlement claim and does not guarantee representation, litigation, or payment.
This case is still developing and has no official claim site yet. Class Action Pulse is not a law firm — submit your details below to be notified and connected with a firm handling the case.
Do you qualify?
Check your eligibility and get help understanding your claim. It's free and takes under a minute.
Sources
Frequently asked questions
What happened in the LHC Group incident?
LHC says an employee may have been targeted by a voice-phishing attack and that a threat actor later used stolen credentials to access files through a third-party vendor platform between April 7 and April 15, 2026.
What information may have been involved?
The information varied by person and may have included identity and demographic data, clinical and treatment information, health insurance data, Medicare or Medicaid identifiers, and limited Social Security number or financial information.
Did LHC find evidence that the information was misused?
LHC's notice says it had no evidence or reason to believe the information had been misused. That is the company's statement based on its investigation at the time of notice and is not a guarantee that misuse cannot occur or later be discovered.
Is the December 4 deadline a lawsuit deadline?
No. It is the deadline stated in LHC's notice for notified individuals to enroll in the offered IDX credit monitoring and identity protection. No settlement claim or court deadline was verified.
Has a class action settlement been approved?
No. Attorneys are evaluating possible claims, but the reviewed sources do not establish a certified class, approved settlement, official compensation claim form, or guaranteed payment.
