LHC Group, Inc. Data Breach Lawsuit Investigation

Active investigation · Free, confidential case review
Call (954) 799-5914
Data Breaches / LHC Group
Active investigation Data breach · Healthcare Notices mailed Sep 4, 2026

Received an April 2026 breach notice from LHC Group?

Dapeer Law, P.A. is investigating a potential class action against LHC Group, Inc., a home health and hospice care provider, on behalf of patients whose personal and health information may have been exposed in the April 2026 cyber incident.

Submit your claim See what to do No fee unless we recover for you
Breach window
April 7 to 15, 2026
Credentials stolen in a vishing attack
Notification delay
About 5 months
Detected April 2026, notices September 2026
Credit monitoring
24 months
Through IDX identity protection
Eligibility

Who may qualify

You may be eligible to participate in a class action if any of the following applies:

  • You received a data breach notification letter from LHC Group dated April 2026.
  • Your letter offered enrollment in free IDX credit-monitoring and identity-protection services.
  • You had personal or medical information held by LHC Group in its capacity as a home health and hospice care provider.
  • No proof of harm required to consult with counsel. You do not need to have already suffered identity theft to explore your legal options.
  • Excluded: individuals who did not receive a breach notice and whose information was not involved in the incident.

Not sure if you qualify?

Send us your notice, we'll confirm your eligibility at no cost.

Check eligibility
Background

What happened

According to a notice LHC Group, Inc. filed with the Massachusetts Attorney General, the company learned on April 7, 2026 that one of its employees had been targeted in a voice phishing attack, commonly called vishing, in which a caller impersonating a trusted source persuaded the employee to hand over account credentials. LHC Group reports that a third-party technology vendor that supports its referral management, care coordination, and clinical workflow functions detected suspicious activity tied to that employee's user account at the same time. LHC Group says it secured its systems, disabled the compromised credentials, retained outside forensic specialists, and notified the Federal Bureau of Investigation.

LHC Group reports that its investigation determined an unauthorized party used the stolen credentials to download a large volume of documents containing patient protected health information between April 7 and April 15, 2026, and that the identities of the affected individuals were finalized on July 9, 2026. Written notices were mailed and the incident was reported to the Massachusetts Attorney General on September 4, 2026, covering 4,812 Massachusetts residents. The notice indicates that the files may have contained names, addresses, dates of birth and other demographic details, Social Security numbers in limited instances, clinical information such as diagnosis codes, dates of service, treatment plans and provider details, health insurance policy and member information, Medicare and Medicaid identification numbers, and limited financial information. LHC Group is offering affected individuals two years of complimentary IDX credit-monitoring and identity-protection services. The gap between the April 2026 intrusion and the September 2026 notices, roughly five months, is one of the questions our investigation is examining.

Because the information reportedly involved includes protected health information, government health program identification numbers, and Social Security numbers in some cases, affected patients may face an elevated risk of identity theft, medical identity theft, and fraudulent billing under their insurance or Medicare and Medicaid numbers. Medical information can carry heightened sensitivity and may be subject to protections under state law and federal health privacy rules.

Vishing Attack Stolen Credentials Protected Health Information Medicare and Medicaid ID Numbers Massachusetts Attorney General
Action plan

What to do if you received a letter

1

Keep your notice letter

Do not discard it. Your letter contains the enrollment code for credit monitoring and is important evidence if you decide to participate in a lawsuit.

2

Enroll in the free 24-month credit monitoring

Enroll in the IDX credit-monitoring and identity-protection service offered in your letter before the stated deadline. Accepting this benefit does not waive your right to pursue legal action.

3

Place a fraud alert or credit freeze

Contact Equifax, Experian, and TransUnion to place a fraud alert or freeze on your file. Request a free weekly credit report from AnnualCreditReport.com, and use the FTC's IdentityTheft.gov recovery guide.

4

Speak with a data breach attorney

Consultations with Dapeer Law are free and confidential. We'll review your notice, explain your options, and advise whether you may be eligible to join a class action.

Submit your notice for a free review

Two minutes online. A licensed attorney reviews every submission.

Submit your claim
Timeline

Breach timeline

April 7, 2026 Passed
Vishing attack on employee account detected, FBI notified
April 7 to 15, 2026 Passed
Patient documents downloaded using stolen credentials
July 9, 2026 Passed
Identities of affected individuals finalized
September 4, 2026 Passed
Notice filed with Massachusetts Attorney General, letters mailed
Pending Active
Potential class action filing
Statutes of limitations vary by state and legal theory, typically one to six years. Waiting can permanently bar your claim.
Possible recovery

Compensation you may be entitled to

Out-of-pocket expenses

Credit freezes, identity restoration services, and other costs incurred responding to the breach.

Time spent monitoring

Hours spent reviewing accounts, disputing fraudulent charges, and dealing with identity theft issues.

Identity theft & fraud losses

Unreimbursed funds stolen from accounts, unauthorized credit lines, or tax refund fraud tied to the breach.

Statutory damages

Certain state data breach and consumer protection statutes provide for fixed damages regardless of actual loss.

Injunctive relief

Court orders requiring LHC Group to implement stronger data security practices going forward.

Compensation categories depend on applicable state law, the types of data exposed, and documented losses. No recovery is guaranteed.

FAQ

Common questions

I received a data breach letter from LHC Group. What should I do? +

Keep your notice letter, enroll in the complimentary IDX credit-monitoring and identity-protection service before the deadline, and review your medical bills, insurance Explanation of Benefits statements, and bank statements for services or charges you do not recognize. Consider placing a fraud alert or security freeze on your credit files, be cautious with unsolicited calls or emails asking you to confirm personal information, and contact a data breach attorney to understand your options.

Am I eligible to join a class action against LHC Group? +

If you received a notice letter dated September 4, 2026 from LHC Group, or your information was among the patient records involved in the incident, you may be eligible. Factors that affect eligibility include your state of residence, the categories of your data exposed, and whether you experienced any economic or emotional harm.

How much money could I receive from a class action lawsuit? +

Data breach class action recoveries vary significantly. Settlements typically range from a few hundred dollars for basic out-of-pocket losses to several thousand dollars for documented identity theft, with class size, damages, and negotiation all affecting the final amount. No payout is guaranteed, and this investigation has not yet resulted in a settlement.

What personal information was exposed in the breach? +

The notice reports that the files involved may have contained names, addresses, dates of birth and demographic details, Social Security numbers in limited instances, clinical information including diagnosis codes, dates of service and treatment plans, health insurance policy and member information, Medicare and Medicaid identification numbers, and limited financial information. Not every element applied to every patient, so review your individual letter closely and keep it.

Did LHC Group offer free credit monitoring? +

Yes. LHC Group is offering two years of complimentary IDX credit-monitoring and identity-protection services. Enroll before the deadline stated in your letter using the activation code provided. Accepting this service does not waive your right to pursue legal action.

How many people were affected by the LHC Group breach? +

LHC Group reported the incident to the Massachusetts Attorney General as affecting 4,812 Massachusetts residents. The total number of individuals affected across all states has not been separately disclosed in the public filing. We will update this page as more becomes known.

Is there a deadline to take legal action? +

Yes. Statutes of limitations for data breach claims vary by state and legal theory, typically ranging from one to six years. Waiting can permanently bar your claim. Contact us as soon as possible for a free evaluation.

How do I get a copy of the official breach notice? +

LHC Group's notice was filed with the Massachusetts Attorney General and is available for download from that office. Dapeer Law can also help you obtain a copy of the notice during a free consultation.

References

Sources & references

Attorney advertising. This page is provided for informational purposes only. It does not constitute legal advice or form an attorney-client relationship. Dapeer Law, P.A. is not affiliated with LHC Group, Inc., IDX, or any credit bureau. Prior results do not guarantee a similar outcome. All information regarding the data incident is drawn from the official notification filed with Massachusetts Attorney General on September 4, 2026.
Free, confidential case review

Don't let the deadline decide for you. Submit your claim today.

You only have a limited window to act. Our team will review your notice, explain your options, and tell you whether you may be eligible to recover compensation, at no cost to you.

Why Dapeer Law

Practice focusConsumer class actions
Licensed inFL · NY · NJ · IL
Case review fee$0
Response timeSame business day
Free case review
Confidential · 2 minutes
Submit claim →
Next
Next

Fraser Trebilcock Data Breach Lawsuit Investigation