Enhabit Home Health & Hospice, operating under the entity Advanced Homecare Management, LLC, has notified more than 23,000 patients that their clinical and personal information was exposed after attackers used compromised login credentials to reach Doctor Alliance, a third-party platform the company uses to route physician orders and clinical documentation between doctors and home health agencies.
Enhabit's own systems were not breached directly. According to the company's notice, the intrusion occurred through valid but stolen credentials at Doctor Alliance during two separate windows — October 31 through November 6, and November 14 through 17, 2025. The company reported the incident to the U.S. Department of Health and Human Services on February 5, 2026, and has since notified affected individuals and multiple state attorneys general.
What was — and wasn't — exposed
A total of 23,154 individuals in the United States were affected. The information accessed included names, addresses, dates of birth, gender, physician names, medical record numbers, clinical information and health plan numbers. Enhabit says Social Security numbers and financial account information were not part of the exposure, which limits — but does not eliminate — the risk of identity theft compared with breaches that include financial credentials.
Enhabit is advising affected patients to monitor their credit reports and consider placing a fraud alert or credit freeze, and has set up a dedicated support line for questions about the incident.
The vendor problem home health can't outsource away
The breach is a case study in a risk that has become routine across healthcare: the weak point often isn't the provider itself, but a platform it depends on to move information between clinicians. Doctor Alliance exists specifically to streamline the exchange of orders and documentation between physicians and home health and hospice agencies — the kind of connective-tissue software that rarely gets the security scrutiny of a hospital's core electronic health record, but that sits on top of exactly the same sensitive data.
For an industry built on frequent handoffs between physicians, agencies, family caregivers and, increasingly, remote monitoring platforms, that creates a wide and growing attack surface. A compromised credential at any single point in that chain can expose patient records that never touched the provider's own network — which is precisely what happened here. Home health and hospice organizations are increasingly being told by security researchers to treat every clinical integration partner as a potential point of failure, not just their own infrastructure, and to demand the same credential hygiene and monitoring from vendors that they enforce internally.

