LHC Group Data Breach Exposes Patient Records, Legal Scrutiny Follows
Healthcare provider LHC Group has disclosed a data breach after discovering in April 2026 that an employee had likely fallen victim to a phishing attack. A technology vendor separately flagged suspicious activity on an LHC account, leading to an investigation that found stolen credentials had been used to access patient files between April 7 and April 15, 2026.
The compromised information may include names, dates of birth, Social Security numbers, health information, health insurance details, government identification numbers, and financial data. LHC began identifying affected individuals in July and started notifying patients in early September 2026, several months after the breach was first detected.
A national law firm, Edelson Lechtzin LLP, has since announced it is investigating potential class action claims on behalf of affected individuals. This case highlights how a single successful phishing attempt can lead to prolonged unauthorised access and large-scale exposure of sensitive health records.
Key Takeaway: Small businesses handling health or personal data should train staff to recognise phishing attempts and ensure account activity is actively monitored so unauthorised access is caught quickly, not months later.