Article

TMHP Reports Data Security Incident Affecting Medicaid Clients and Providers

TMHP reported a data security incident that may have involved information associated with 1,828 Medicaid clients and 217 health care providers. Notices and identity-protection information were mailed to affected individuals.

Illustration representing the TMHP data security incident and notifications to Medicaid clients and providers

Watch the video walkthrough

TMHP issued a June 2026 notice concerning a data security incident that may have involved personal information associated with Medicaid clients and health care providers.

According to TMHP's notice, the incident may have affected information associated with 1,828 Medicaid clients and 217 health care providers. TMHP notified the individuals identified through its investigation and offered identity-protection services through IDX.

What TMHP reported

TMHP reported unauthorized access to certain systems between February 5 and March 26, 2026. TMHP determined on April 20, 2026, that a fraud-related incident had occurred and investigated the potentially affected records.

The notice does not state that every Texas Medicaid client or provider was affected. It applies to the individuals whose information may have been involved.

Information that may have been involved

For affected Medicaid clients, TMHP said the information may have included items such as the Medicaid number, name, date of birth, Social Security number, address, Medicaid benefit or card information, and health information.

For affected health care providers, the information may have included name, contact information, medical-license information, financial information, driver's-license number, Social Security number, Tax ID, and other information maintained in the Provider Enrollment and Management System.

The type of information varied by individual; the notice does not say that every listed data element was involved for every affected person.

How TMHP responded

TMHP reported disabling the unauthorized access, blocking suspicious network activity, reviewing potentially affected records, verifying users before restoring access, and making additional security and process improvements.

At the time of the notice, TMHP stated that it had no indication that the information had been misused.

Identity-protection information

Individuals who received a TMHP notification should follow the instructions in their letter for the identity-protection services offered through IDX. The enrollment process uses a unique code provided to the affected individual.

Do not publish or share an enrollment code, and be cautious of unsolicited calls, emails, or text messages requesting an enrollment code, Social Security number, Tax ID, password, or payment for a service described as free in the official notice.

Steps affected individuals can consider

Review credit reports and financial, insurance, health-plan, and benefit information for activity you do not recognize. The Federal Trade Commission provides current guidance on credit freezes, fraud alerts, and identity-theft recovery at IdentityTheft.gov.

Free credit reports are available through AnnualCreditReport.com, the federally authorized source for reports from the nationwide credit bureaus.

If personal information has been misused, report the identity theft through IdentityTheft.gov and contact the affected financial institution, health plan, government agency, or other organization using verified contact information.

What providers should do

A provider that received a TMHP notification should review the letter carefully, route it to the appropriate owner, administrator, privacy or security contact, monitor relevant financial and enrollment information, and follow the official protection instructions.

Do not assume that reading about the incident means your organization was affected. TMHP sent notices to the clients and providers identified through its investigation.

Does the notice identify ElderSuite as involved?

No. The TMHP notice concerns access to TMHP systems and does not identify ElderSuite as involved. It does not direct providers to change ElderSuite settings or state that ElderSuite data was accessed through this incident.

Continue normal ElderSuite security practices, including protecting individual credentials, limiting employee permissions, keeping software current, and disabling access for staff who no longer require it.

Where to get more information

Use the official TMHP notice linked with this article for the incident details and the contact and enrollment instructions provided to affected individuals.

This article provides general informational guidance. Organizations should consult their privacy, security, insurance, or legal advisers when determining whether additional action is required.

Follow ElderSuite in Google

Add ElderSuite as a Preferred Source to help Google show you more of our adult day care articles, industry updates, and resources.

Review the official TMHP notice and follow the instructions in your notification letter if TMHP identified you or your organization as affected.

ElderSuite is adult day care software for attendance, Medicaid billing, nursing documentation, and CACFP. You can try it free for 30 days.

Start a Free Trial

Related resources

Back to Adult Day Care Resources