---
title: "Texas Medicaid and Healthcare Partnership unauthorized-access incident"
description: "Evidence-backed account of Texas Medicaid and Healthcare Partnership unauthorized-access incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/texas-medicaid-healthcare-partnership-unauthorized-access-2026"
markdown_url: "https://www.ally.security/incidents/texas-medicaid-healthcare-partnership-unauthorized-access-2026.md"
stix_url: "https://www.ally.security/incidents/texas-medicaid-healthcare-partnership-unauthorized-access-2026/stix.json"
---

# Texas Medicaid and Healthcare Partnership unauthorized-access incident

An unknown person or people accessed information in TMHP systems over a seven-week interval. Personal, Medicaid, and health information accessed by an unknown person or people.

Last modified Aug 9, 2026 · 3 sources

## Summary

- **Environment:** Not publicly identified
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** TMHP offered 12 months of IDX credit and CyberScan monitoring, identity-recovery help, and up to $1 million in insurance reimbursement.

## What happened

An unknown person or people accessed information in [TMHP](https://www.tmhp.com/) systems over a seven-week interval. [1](#source-1)

## Impact

Personal, Medicaid, and health information accessed by an unknown person or people. [1](#source-1) [2](#source-2) [3](#source-3)

Documented data types include:

- Social Security numbers [1](#source-1)
- Health insurance information — Medicaid benefits and Medicaid-card information. [1](#source-1)
- Clinical information — Health information including vaccines and prescriptions. [1](#source-1)
- Dates of birth [1](#source-1)
- Names [1](#source-1)
- Contact information — The notice specifically lists addresses. [1](#source-1)

A cited record reports 1 individual (Massachusetts resident affected according to incident report 2026-1004; not a national total). [2](#source-2)

A cited record reports 2,045 individuals (Individuals listed for TMHP in the HHS OCR incident portal; regulator-reported and not independently verified; as of 2026-08-08). [1](#source-1) [2](#source-2) [3](#source-3)

TMHP said it had no indication that affected personal information had been misused. [1](#source-1)

An unknown person or people accessed affected individuals' information in TMHP systems. [1](#source-1)

## Timeline

### February 5, 2026 — Activity began

Start of the access interval stated by TMHP. [1](#source-1)

### March 26, 2026 — Documented activity ended

End of the access interval stated by TMHP. [1](#source-1)

### April 20, 2026 — Discovery

Date TMHP says it found that information may have been accessed. [1](#source-1)

### June 18, 2026 — Documented event

Date printed on the English and Spanish notification letter. [1](#source-1)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT\&CK technique.

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

The accessed fields also included Medicaid numbers and Medicaid card information. TMHP offered 12 months of IDX credit and CyberScan monitoring, identity-recovery help, and up to $1 million in insurance reimbursement. TMHP disabled the access, blocked suspicious IP locations, reviewed affected accounts and records, restored legitimate access after verifying email addresses, and began a full review and improvements. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1](#source-1)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/texas-medicaid-healthcare-partnership-unauthorized-access-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Notice of unauthorized access — Massachusetts filing

official · Texas Medicaid and Healthcare Partnership

<https://www.mass.gov/doc/2026-1004-texas-medicaid-and-healthcare-partnership/download>

<a id="source-2"></a>

### 2026 Data Breach Notification Report

regulatory · Massachusetts Office of Consumer Affairs and Business Regulation

<https://www.mass.gov/doc/data-breach-report-2026/download>

<a id="source-3"></a>

### Breach Portal current investigation table

regulatory · U.S. Department of Health and Human Services Office for Civil Rights

<https://ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Exposed Data Category · 100% confidence · current**  
   TMHP Medicaid-member data exposure: Social Security numbers
2. **Affected Organization · 100% confidence · current**  
   February–March 2026 TMHP unauthorized-access incident: Texas Medicaid and Healthcare Partnership
3. **Resulted In · 100% confidence · current**  
   February–March 2026 TMHP unauthorized-access incident: TMHP Medicaid-member data exposure
4. **Resulted In · 100% confidence · current**  
   February–March 2026 TMHP unauthorized-access incident: TMHP said it had no indication that affected personal information had been misused.
5. **Exposed Data Category · 100% confidence · current**  
   TMHP Medicaid-member data exposure: Health insurance information
6. **Exposed Data Category · 100% confidence · current**  
   TMHP Medicaid-member data exposure: Clinical information
7. **Exposed Data Category · 100% confidence · current**  
   TMHP Medicaid-member data exposure: Dates of birth
8. **Resulted In · 100% confidence · current**  
   TMHP Medicaid-member data exposure: An unknown person or people accessed affected individuals' information in TMHP systems.
9. **Resulted In · 100% confidence · current**  
   TMHP Medicaid-member data exposure: The accessed fields also included Medicaid numbers and Medicaid card information.
10. **Began At · 100% confidence · current**  
   February–March 2026 TMHP unauthorized-access incident: 2026-02-05
11. **Resulted In · 100% confidence · current**  
   TMHP affected-individual notification: TMHP offered 12 months of IDX credit and CyberScan monitoring, identity-recovery help, and up to $1 million in insurance reimbursement.
12. **Affected Individual Count · 100% confidence · current**  
   TMHP Medicaid-member data exposure: 1 individual
13. **Affected Individual Count · 100% confidence · current**  
   TMHP Medicaid-member data exposure: 2,045 individual
14. **Exposed Data Category · 100% confidence · current**  
   TMHP Medicaid-member data exposure: Names
15. **Resulted In · 100% confidence · current**  
   February–March 2026 TMHP unauthorized-access incident: TMHP disabled the access, blocked suspicious IP locations, reviewed affected accounts and records, restored legitimate access after verifying email addresses, and began a full review and improvements.
16. **Occurred At · 100% confidence · current**  
   TMHP affected-individual notification: 2026-06-18
17. **Exposed Data Category · 100% confidence · current**  
   TMHP Medicaid-member data exposure: Contact information
18. **Resulted In · 100% confidence · current**  
   February–March 2026 TMHP unauthorized-access incident: TMHP affected-individual notification
19. **Ended At · 100% confidence · current**  
   February–March 2026 TMHP unauthorized-access incident: 2026-03-26
20. **Discovered At · 100% confidence · current**  
   February–March 2026 TMHP unauthorized-access incident: 2026-04-20

</details>
