TMHP reported a data security incident that may have involved information associated with 1,828 Medicaid clients and 217 health care providers. Notices and identity-protection information were mailed to affected individuals.

The Texas Medicaid & Healthcare Partnership has issued a notice concerning a data security incident that may have involved personal information associated with Medicaid clients and health care providers.
According to the notice dated June 19, 2026, the incident may have affected information associated with 1,828 Medicaid clients and 217 health care providers.
TMHP mailed notices to the individuals whose information was involved and is offering free identity-theft protection services through IDX.
TMHP stated that unauthorized access to certain systems occurred between February 5 and March 26, 2026.
On April 20, 2026, TMHP determined that a fraud-related incident had occurred. TMHP then began investigating the scope of the incident and identifying potentially affected records.
The notice does not state that every Texas Medicaid client or provider was affected. It applies to the individuals whose information may have been involved in the incident.
The type of information potentially involved depends on whether the affected person was a Medicaid client or a health care provider.
For the 1,828 Medicaid clients identified in the notice, the information may have included:
For the 217 health care providers identified in the notice, the information may have included:
The notice uses the phrase “may have been accessed.” It does not state that every type of information was involved for every affected person.
TMHP reported taking several actions after discovering the incident, including:
TMHP mailed notices on June 18, 2026, to the Medicaid clients and health care providers whose information was involved.
At the time of the notice, TMHP stated that it had no indication that the information had been misused.
TMHP is offering free identity-theft protection services through IDX to the affected Medicaid clients and health care providers.
Individuals who received a notification letter should follow the enrollment instructions contained in that letter. Enrollment requires the unique code provided to the individual.
Questions about the incident or enrollment may be directed to IDX at:
1-833-788-9712
The assistance line is available Monday through Friday from 8 a.m. to 8 p.m. Central Time.
Do not share an individual enrollment code publicly or provide it in response to an unsolicited call, email, or text message.
TMHP recommends that affected clients and providers regularly review their records and promptly report suspicious activity.
The Federal Trade Commission also recommends several steps following a data breach.
Check credit reports for unfamiliar accounts, inquiries, addresses, or debts.
Free credit reports are available through AnnualCreditReport.com, the federally authorized website for obtaining reports from Equifax, Experian, and TransUnion.
A credit freeze restricts access to a credit report, making it more difficult for someone to open a new credit account using another person’s identity.
A freeze is free to place and lift, but it must be placed separately with all three nationwide credit bureaus. The FTC provides current instructions through its data-breach recovery guidance.
A fraud alert tells businesses to take additional steps to verify identity before opening a new credit account.
An initial fraud alert is free and lasts one year. Unlike a credit freeze, an individual can contact one nationwide credit bureau, and that bureau must notify the other two.
The FTC explains the differences between these protections in its guidance on credit freezes and fraud alerts.
Review bank, credit-card, insurance, health-plan, and benefit information for activity that is not recognized.
Contact the appropriate institution using a verified phone number or website if suspicious activity is found.
If personal information has been misused, report it at IdentityTheft.gov. The site can create an FTC Identity Theft Report and a personalized recovery plan.
Providers that receive a TMHP notification should:
Providers should not assume that receiving industry news about the incident means their information was involved. TMHP mailed individual notices to the Medicaid clients and providers identified through its investigation.
Publicly reported security incidents can lead to phishing attempts from people impersonating the affected organization or its response provider.
Be cautious if someone:
Verify requests using the telephone number printed in the official notification letter. Do not rely on contact information supplied in an unexpected message.
No. The TMHP notice addresses unauthorized access to certain TMHP systems and does not identify ElderSuite as involved.
The notice also does not direct providers to change ElderSuite settings or indicate that local ElderSuite data was accessed through this incident.
Providers should continue following their normal ElderSuite security procedures, including protecting employee credentials, limiting access according to job responsibilities, maintaining current software versions, and promptly disabling access for employees who no longer require it.
Affected individuals should refer to the notification letter mailed by TMHP and contact IDX at 1-833-788-9712 with questions about the incident or identity-protection enrollment.
The original TMHP notice is available as a downloadable document with this article.
Anyone who discovers actual misuse of personal information can report it and obtain a recovery plan through IdentityTheft.gov.
This article is provided for general informational purposes. Providers should consult their privacy, security, insurance, or legal advisers when determining whether additional organizational action is required.
ElderSuite is adult day care software for attendance, Medicaid billing, nursing documentation, and CACFP. You can try it free for 30 days.
Start a Free Trial