Almeida Law Group is investigating a data breach at LHC Group, Inc. The breach occurred on April 7th–15th, 2026 and was discovered on April 7th, 2026. If you were affected, contact Almeida Law Group.
About LHC Group, Inc
LHC Group, Inc. is a national healthcare provider founded in 1994 and headquartered in Lafayette, Louisiana. The company specializes in post-acute care services, delivering home health, hospice, home- and community-based, and facility-based care primarily to Medicare beneficiaries. It operates 964 locations across 37 states and employs approximately 30,000 people. In February 2023, UnitedHealth Group completed a $5.4 billion acquisition of LHC Group, making it a wholly owned subsidiary of UnitedHealth’s Optum division. Because LHC Group provides direct medical care and billing services, it routinely handles sensitive personal, medical, and insurance information — making any unauthorized access to its systems a serious concern for affected individuals.
What Happened?
LHC Group, Inc. was listed in a Texas Attorney General data security breach report (record ID BR-0005312), published on September 4th, 2026. According to that filing, an unauthorized party gained access to LHC Group’s systems during a window beginning April 7th, 2026 and ending April 15th, 2026. The breach was discovered on April 7th, 2026 — the same day it began — and affected a total of 162,578 individuals. Compromised information included names, addresses, dates of birth, Social Security numbers, medical information, and health insurance information. LHC Group notified affected consumers by U.S. Mail. No ransomware group, specific threat actor, or detailed attack vector has been publicly identified for this incident, and no independent media coverage of it was found as of the report date.
It is worth noting that LHC Group was previously connected to a separate, smaller breach involving its technology vendor Doctor Alliance. According to HIPAA Journal, an unauthorized third party accessed a Doctor Alliance web portal between October 31st, 2025 and November 17th, 2025, affecting 8,644 individuals. That earlier incident involved a vendor system, not LHC Group’s own infrastructure, and is distinct from the April 2026 breach described here. The Srourian Law Firm has publicly announced a class action investigation tied to that earlier vendor breach. No public litigation or investigation specifically connected to the current April 2026 incident had been reported as of September 4th, 2026.
Key Facts at a Glance
- Company or Organization: LHC Group, Inc.
- Industry: Healthcare – Home Health, Hospice, and Post-Acute Care Services
- Location: Lafayette, Louisiana
- Incident type: Unauthorized access to systems
- Date of breach: April 7th, 2026 – April 15th, 2026
- Date breach discovered: April 7th, 2026
- Date of consumer notification: Reported to Texas Attorney General on September 4th, 2026; consumers notified by U.S. Mail
- Total persons affected: 162,578
- Prior breach: Yes — separate October–November 2025 vendor breach via Doctor Alliance (8,644 individuals)
- Litigation status: Class action investigation announced by Srourian Law Firm related to the prior 2025 Doctor Alliance vendor breach; no litigation reported for the current April 2026 breach
- Source: Texas Attorney General Data Security Breach Report – BR-0005312; HIPAA Journal – May 2026 Data Breach Round Up; McKnight’s Home Care – UnitedHealth Group completes $5.4B purchase of LHC Group; Srourian Law Firm – LHC Group Breach Investigation
What Should You Do?
If you received a notification letter from LHC Group, review it carefully to understand what information of yours was involved. Because this breach included Social Security numbers, medical information, and health insurance data, you should take several protective steps right away. Enroll in any identity theft protection service LHC Group offers, and make note of any enrollment deadline stated in your notice. Place a fraud alert or credit freeze with the three major credit bureaus — Equifax, Experian, and TransUnion — and monitor your credit reports regularly through AnnualCreditReport.com. Review your Explanation of Benefits statements from your health insurer and check your medical records for any services you do not recognize, which could signal fraudulent use of your health information. If you discover signs of identity theft or unauthorized activity, report it at IdentityTheft.gov for step-by-step guidance on recovery.
Your Legal Rights
If your personal or health information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.