D.C. Health Agency Printed Incorrect Portal URL on Cards

A clerical error on medical identification cards directed Washington residents to a phishing site.

Updated on Sept. 22, 2026 in Cybersecurity

Isometric editorial illustration of a large administrative stamp and a tangled ink ribbon, representing a government clerical error.
The D.C. Department of Health Care Finance reported that an incorrect URL printed on medical identification cards redirected Washington residents to a phishing site. AI Illustration. Upload story photo >

Live Poll

Do you trust your local government agencies to keep official digital communications secure and accurate?

The D.C. Department of Health Care Finance mailed medical identification cards containing an incorrect website address that redirected users to an adult-content phishing site. The agency confirmed that its internal systems remain uncompromised despite the error.

Why it matters

This incident highlights the security risks inherent in administrative oversight, as simple typos on physical correspondence can inadvertently bridge users toward malicious web infrastructure.

The agency-printed URL directed residents to a domain no longer owned or utilized by the District of Columbia. While the phishing site utilized this abandoned domain, the Department of Health Care Finance systems remain secure.

The players

D.C. Department of Health Care Finance

The local government agency responsible for managing the Medicaid program and issuing official medical documentation to residents.

Office of the Chief Technology Officer

The agency tasked with overseeing the digital infrastructure and technical security standards for the District of Columbia government.

The details

The error occurred when the agency failed to update a legacy URL on printed medical identification materials. When residents entered the printed address into a browser, the domain redirected them to a phishing site—a fraudulent website designed to deceive visitors into providing sensitive information—containing adult content. The D.C. Department of Health Care Finance is currently collaborating with the Office of the Chief Technology Officer to audit physical materials and prevent similar routing issues.

Timeline

  1. July 2026: Kristin Wallace returned to the District.

  2. Early August 2026: Wallace applied for Medicaid coverage.

  3. September 20, 2026: Wallace opened the official DHCF letter containing the erroneous web address.

  4. September 21, 2026: Wallace publicly disclosed the experience on Reddit.

The Tech Race

This error illustrates a departure from the security rigor expected under established D.C. government cybersecurity protocols. Government agencies must maintain strict lifecycle management for web domains to prevent abandoned links from being hijacked by bad actors.

Residents who received physical identification cards from the Department of Health Care Finance should verify the URL against the official portal. The verified, secure address for all Medicaid-related services in the District is medicaid.dc.gov.

The takeaway

This incident serves as a reminder to always verify the source of digital portals printed on physical government mail before entering personal data. Users should remain vigilant when navigating to government sites that deviate from standard naming conventions.

Further reading

For more on how organizations secure digital assets, visit the Cybersecurity section.

More information

For official account management and benefit status, visit the Official D.C. Medicaid portal.

Live Poll

Do you trust your local government agencies to keep official digital communications secure and accurate?