Chicago Cosmetic Surgery and Dermatology Investigated Following December 2025 Data Breach
Chicago Cosmetic Surgery and Dermatology, a private medical practice in Chicago’s River North neighborhood, reported a data breach to the U.S. Department of Health and Human Services (HHS) on December 22, 2025. The incident, classified as a hacking or IT-related breach, has prompted an investigation by class action law firm Shamis & Gentile P.A., which specializes in data breach litigation.
The practice, which employs between 51 and 200 staff and provides dermatology, cosmetic surgery, and aesthetic treatments, has not publicly disclosed the number of affected individuals or the specific types of compromised data. However, such breaches typically involve exposure of sensitive personally identifiable information (PII), potentially increasing risks of identity theft and fraud.
While the company has not issued a public notice about the incident, affected individuals may have legal recourse under data breach laws. The investigation seeks to determine eligibility for compensation related to damages such as identity theft, financial losses, or emotional distress. No further details on the breach’s scope or response efforts have been released.
Source: https://www.claimdepot.com/investigations/chicago-cosmetic-surgery-and-dermatology-data-breach-2026
Chicago Cosmetic Surgery and Dermatology cybersecurity rating report: https://www.rankiteo.com/company/chicago-cosmetic-surgery-and-dermatology
"id": "CHI1770230798",
"linkid": "chicago-cosmetic-surgery-and-dermatology",
"type": "Breach",
"date": "12/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Healthcare (Dermatology, Cosmetic '
'Surgery, Aesthetic Treatments)',
'location': 'Chicago, River North neighborhood',
'name': 'Chicago Cosmetic Surgery and Dermatology',
'size': '51-200 employees',
'type': 'Private Medical Practice'}],
'attack_vector': 'Hacking/IT Incident',
'data_breach': {'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': 'Personally identifiable '
'information (PII)'},
'date_publicly_disclosed': '2025-12-22',
'description': 'Chicago Cosmetic Surgery and Dermatology reported a data '
'breach to the U.S. Department of Health and Human Services '
'(HHS) on December 22, 2025. The incident, classified as a '
'hacking or IT-related breach, has prompted an investigation '
'by class action law firm Shamis & Gentile P.A. The breach may '
'have exposed sensitive personally identifiable information '
'(PII), increasing risks of identity theft and fraud.',
'impact': {'data_compromised': 'Sensitive personally identifiable information '
'(PII)',
'identity_theft_risk': 'Increased',
'legal_liabilities': 'Potential legal actions under data breach '
'laws'},
'investigation_status': 'Ongoing',
'references': [{'source': 'Class action law firm Shamis & Gentile P.A.'}],
'regulatory_compliance': {'legal_actions': 'Class action investigation '
'underway',
'regulations_violated': 'Potential violations of '
'data breach laws (e.g., '
'HIPAA)',
'regulatory_notifications': 'Reported to U.S. '
'Department of Health '
'and Human Services '
'(HHS)'},
'response': {'third_party_assistance': 'Class action law firm Shamis & '
'Gentile P.A. investigating'},
'title': 'Chicago Cosmetic Surgery and Dermatology Data Breach',
'type': 'Data Breach'}