[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f7fwc4jv7z8bg":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":23,"affectedCount":23,"affectedCountStatus":24,"affectedCountLowerBound":25,"affectedCountUnit":26,"hasEnglishDescription":4,"severity":27,"dataClasses":28,"description":40,"seoTitle":41,"seoTitleEn":42,"seoDescription":41,"seoDescriptionEn":43,"logoUrl":44,"isVerified":4,"isSensitive":4,"isSpamList":45,"isMalware":45,"company":46},"68e3266eda11adda4882517f","dchealth","DC Health Link Data Breach","dc-health-link","dchealthlink.com","2023-03-06T00:00:00.000Z","2023-12-14T19:11:43.000Z","2026-07-09T20:53:57.814Z","2026-07-18T23:49:37.715Z","Third party breach","https:\u002F\u002Fwww.dchealthlink.com\u002Fdata-breach",[16,18,19,20,21,22],"https:\u002F\u002Fwww.nbcwashington.com\u002Fnews\u002Flocal\u002F56000-affected-by-dc-health-link-data-breach\u002F3299215\u002F","https:\u002F\u002Fwww.hipaajournal.com\u002Fdc-health-link-data-breach-caused-by-human-error\u002F","https:\u002F\u002Fstatescoop.com\u002Fdc-health-insurance-exchange-data-breach-congress\u002F","https:\u002F\u002Foversight.house.gov\u002Frelease\u002Fmace-d-c-health-data-breach-resulted-in-sale-of-thousands-of-individuals-information-on-the-dark-web\u002F","https:\u002F\u002Fwww.twingate.com\u002Fblog\u002Ftips\u002Fdc-health-link-data-breach",48145,"known",null,"unknown","Medium",[29,30,31,32,33,34,35,36,37,38,39],"Citizenship statuses","Dates of birth","Email addresses","Employers","Ethnicities","Genders","Names","Phone numbers","Physical addresses","Purchases","Social security numbers","\u003Cp>The DC Health Link data breach is related to the unauthorized disclosure of sensitive personal data of DC Health Link users in the District of Columbia health insurance marketplace during the March 2023 period. This record covers 48,145 unique email addresses. Official notifications report a broader number of affected current and former customers, 56,415 people; therefore, the number on this page refers to the verifiable email coverage and does not have to exactly match the full official notification coverage. The record includes citizenship status, birth dates, email addresses, employers, ethnicities, genders, names, phone numbers, physical addresses, purchase\u002Fplan information, and social security numbers. For this reason, the incident should be treated as high-sensitivity health insurance and identity risk.\u003C\u002Fp>\n\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The data types in the DC Health Link record go far beyond that of an ordinary account record. Name, email address, phone number, and physical address allow for direct contact with the individual. Date of birth and social security number are fields that play a critical role in identity verification and financial application processes. Citizenship status, ethnic background, gender, employer, and health insurance purchase\u002Fplan context provide sensitive information about a person's private life, work relationships, and health insurance preferences. This combination of data holds high value for identity theft, targeted fraud, false insurance claims, and personalized social engineering attempts.\u003C\u002Fp>\n\u003Cp>When the social security number and date of birth are found together, the risk is long-term; these fields cannot be easily changed like a password. Phone and address information make it easier for attackers to reach the user through calls, text messages, mail, or fake institutional notifications. Employer and purchase\u002Fplan information can lead to more convincing impersonation of a person's health insurance relationship. Citizenship and ethnicity fields are also sensitive in terms of privacy. Therefore, registration is not only a matter of account security; it should also be considered in terms of identity misuse, financial fraud, and personal safety.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The number 48,145 used in this record represents the scope of verified unique email addresses. The official notifications from DC Health Link list the number of affected customers as 56,415. These two numbers do not necessarily conflict with each other; one represents the email coverage verifiable in the breach data set, while the other represents the notification and customer impact scope. There may not be an email address for the same person, some records may be maintained through a family member or dependent, or the notification scope may include individuals who do not match with an email. Therefore, the number shown to the user is a narrow control scope.\u003C\u002Fp>\n\u003Cp>The incident belongs to the March 2023 period and became publicly visible with the sharing of the data on an online forum. Investigations reported that the unauthorized access was related to system configuration and human error; however, this page focuses more on user risk than on technical attack details. Records regarding data fields should be kept clear: citizenship statuses, birth dates, email addresses, employers, ethnicities, genders, names, phone numbers, physical addresses, purchase\u002Fplan information, and social security numbers are confirmed fields. The password field is not confirmed for this record.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The individuals at highest risk are users who have applied for individual or family health insurance through DC Health Link, current or former customers, family members, dependents, and employees covered through this marketplace. Since DC Health Link is also associated with members of Congress, their staff, and families, some records may affect high-profile public officials or their relatives. This situation increases the risk of targeted social engineering. Attackers can pose as official agencies or health insurance representatives using real names, addresses, employers, dates of birth, and insurance context.\u003C\u002Fp>\n\u003Cp>The risk of identity theft can affect not only the account holder directly but also family members and dependents. Information about children, spouses, or other family members may have been kept in health insurance applications. Since fields such as social security number, citizenship status, and date of birth remain unchanged for a long time, the risk can continue for years. For those registered with a corporate or public institution email, attackers can use employer information to prepare more convincing notifications. Therefore, registration should be evaluated from both individual and corporate security perspectives.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>The first step for users matched with a DC Health Link registration is to reduce the risk of identity misuse. Credit reports and new account openings should be monitored, and if possible, credit freezes or fraud alert options should be considered. Fake application or financial transaction attempts containing social security number, date of birth, and address information should be tracked. Users should be especially cautious about unexpected messages related to health insurance, taxes, credit, public services, or identity verification. Instead of links in the message, known institutional channels should be used.\u003C\u002Fp>\n\u003Cp>The second step is communication and account security. The email account should be protected with a strong and unique password, multi-factor authentication should be enabled, and unknown sessions and forwarding rules should be checked. Information should not be shared when people calling by phone ask for a verification code, social security number, health insurance information, or additional identification. Requests on behalf of DC Health Link or a health insurance provider should be verified directly through a known communication channel without using the link in the message. Since records may be kept on behalf of family members and dependents, the same checks should also be discussed within the household.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>This incident shows the long-term risk of identity and application data stored in health insurance marketplaces. Users should regularly monitor credit tracking, account opening checks, tax application tracking, and health insurance correspondence. Since the social security number is an area that cannot be changed or is very difficult to change, the risk does not end with short-term password changes alone. Users should develop stricter verification habits for requests that appear official coming via email and phone. If signs of identity theft are observed, they should quickly contact the relevant institutions.\u003C\u002Fp>\n\u003Cp>The lesson to be learned for institutions is that health insurance and public service data should be managed at the highest sensitivity level. Access controls, cloud configurations, report generation permissions, data export processes, and the storage of old reports should be regularly audited. Fields such as citizenship, ethnic origin, social security number, and health insurance plan should not be unnecessarily made widely accessible. In incident response, it is necessary not only to shut down the system but also to provide clear guidance to affected individuals on identity protection, credit monitoring, and secure communication channels.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>If the verification result on this page matches the DC Health Link record, the user should accept the result as highly accurate. First, signs of identity theft and financial abuse should be monitored. Email accounts, health insurance accounts, and utility accounts should be protected; unknown sessions, forwarding rules, and recovery options should be checked. The user should directly verify any unexpected messages received on behalf of DC Health Link or the health insurance provider before clicking any links.\u003C\u002Fp>\n\u003Cp>Although the DC Health Link breach is dated, the social security number, date of birth, address, citizenship status, and health insurance context pose long-term risks. This record should not be viewed merely as a notification of a past incident. The user should continue credit and identity monitoring steps, share possible risks with family members, and apply stricter verification in unexpected health insurance or public service interactions. This approach reduces the risk of long-term misuse of sensitive data.\u003C\u002Fp>","","DC Health Link Data Breach (48.1 Thousand Reported Records)","DC Health Link Data Breach. 48.1 Thousand reported records were reported. Reported data: Citizenship statuses, Dates of birth, Email addresses. Review the…","\u002Fuploads\u002Flogo\u002Fdchealthlink_com.webp",false,{"name":47,"sector":48,"country":49,"website":10,"websiteArchiveUrl":41,"websiteStatus":41,"websiteCheckedAt":25},"DC Health Link","Health insurance marketplace","United States"]