LHC Group
Sep 2026 · Graded Attested · Healthcare and Life Sciences · Beyond the filings
LHC GroupSep 2026
LHC Group's breach traces to a single phone call: a vishing scheme talked one employee out of login credentials, and those credentials opened patient records with no further resistance. The attack vector was a voice, not a vulnerability, which means the trust boundary was a single person's judgment on a single afternoon. Clinical summaries, diagnosis codes, Medicare and Medicaid IDs, and in some cases Social Security numbers all sat behind that one login. If your entire security architecture can be defeated with a phone call, the attackers weren't brilliant, the system was built wrong.
LHC Group data breach impacts thousands
Not yet quantified
AAttestedHealthcare and Life SciencesAbout this record
This incident is beyond the filings: attributed to a company statement, a regulator or court record, or a news report, and graded Attested or Inferred. Every figure links to the source it was read from; if we have read one wrong, tell us at info@hackerinahoodie.com. This index never sums figures across incidents. See the methodology.