Texas Medicaid and Healthcare Partnership unauthorized-access incident

An unknown person or people accessed information in TMHP systems over a seven-week interval. Personal, Medicaid, and health information accessed by an unknown person or people.

Last modified

Summary

  • Environment: Not publicly identified
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: TMHP offered 12 months of IDX credit and CyberScan monitoring, identity-recovery help, and up to $1 million in insurance reimbursement.
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

An unknown person or people accessed information in TMHP systems over a seven-week interval. [1]

Impact

Personal, Medicaid, and health information accessed by an unknown person or people. [1][2][3]

Documented data types include:

  • Social Security numbers [1]
  • Health insurance information — Medicaid benefits and Medicaid-card information. [1]
  • Clinical information — Health information including vaccines and prescriptions. [1]
  • Dates of birth [1]
  • Names [1]
  • Contact information — The notice specifically lists addresses. [1]

A cited record reports 1 individual (Massachusetts resident affected according to incident report 2026-1004; not a national total). [2]

A cited record reports 2,045 individuals (Individuals listed for TMHP in the HHS OCR incident portal; regulator-reported and not independently verified; as of 2026-08-08). [1][2][3]

TMHP said it had no indication that affected personal information had been misused. [1]

An unknown person or people accessed affected individuals’ information in TMHP systems. [1]

Timeline

  1. Activity began

    Start of the access interval stated by TMHP.

    [1]
  2. Documented activity ended

    End of the access interval stated by TMHP.

    [1]
  3. Discovery

    Date TMHP says it found that information may have been accessed.

    [1]
  4. Documented event

    Date printed on the English and Spanish notification letter.

    [1]
  5. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT&CK technique.

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

The accessed fields also included Medicaid numbers and Medicaid card information. TMHP offered 12 months of IDX credit and CyberScan monitoring, identity-recovery help, and up to $1 million in insurance reimbursement. TMHP disabled the access, blocked suspicious IP locations, reviewed affected accounts and records, restored legitimate access after verifying email addresses, and began a full review and improvements. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1]