Heart Care Centers of Illinois: Healthcare phishing breach exposes SSNs, medical records for 15 months

Heart Care Centers of Illinois: Healthcare phishing breach exposes SSNs, medical records for 15 months

HCCI Discloses 15-Month Phishing Breach Exposing Sensitive Patient Data

Heart Care Centers of Illinois (HCCI), a cardiology practice in Palos Park, Illinois, reported a data breach stemming from a phishing attack that compromised an employee’s email account for 76 days from August 22 to November 6, 2024 before going undetected for 15 months. The incident was only discovered on January 15, 2025, during an unrelated investigation into a separate, unsuccessful phishing attempt.

The breach exposed a wide range of sensitive data, including names, Social Security numbers, dates of birth, driver’s license and state ID numbers, payment card details, financial account information, passport numbers, medical treatment records, prescription histories, and health insurance data. While HCCI stated it had no evidence of data misuse, the exposed information could enable financial fraud, medical identity theft, and long-term risks to victims’ medical records.

HCCI engaged third-party forensic specialists to investigate the breach and later hired a data analytics firm to review the compromised email account. The secondary review concluded on June 11, 2025, delaying notifications to affected individuals until July 10, 2025 nearly six months after discovery. The practice is offering complimentary credit monitoring and identity restoration services through Epiq, with an enrollment deadline of October 31, 2025.

Under HIPAA regulations, HCCI was required to notify affected individuals within 60 days of discovery and report the breach to the U.S. Department of Health and Human Services. The extended 15-month dwell time the period between compromise and detection highlights significant gaps in phishing detection and incident response, a concern for cyber insurers assessing healthcare clients. The breach aligns with broader industry trends, where phishing and social engineering attacks remain the leading cause of cyber losses in the healthcare sector.

The incident underscores the underwriting implications of prolonged undetected breaches, particularly in an industry where medical and financial data are high-value targets for fraud.

Source: https://www.insurancebusinessmag.com/us/news/cyber/healthcare-phishing-breach-exposes-ssns-medical-records-for-15-months-582950.aspx

Heartland Health Centers cybersecurity rating report: https://www.rankiteo.com/company/heartland-health-centers

"id": "HEA1784558364",
"linkid": "heartland-health-centers",
"type": "Breach",
"date": "8/2024",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Patients (number not specified)',
                        'industry': 'Healthcare',
                        'location': 'Palos Park, Illinois, USA',
                        'name': 'Heart Care Centers of Illinois (HCCI)',
                        'type': 'Healthcare Provider'}],
 'attack_vector': 'Email',
 'customer_advisories': 'Credit monitoring and identity restoration services '
                        'offered through Epiq (enrollment deadline: October '
                        '31, 2025)',
 'data_breach': {'personally_identifiable_information': 'Names, Social '
                                                        'Security numbers, '
                                                        'dates of birth, '
                                                        'driver’s license and '
                                                        'state ID numbers, '
                                                        'passport numbers',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Personally Identifiable '
                                              'Information (PII)',
                                              'Protected Health Information '
                                              '(PHI)',
                                              'Financial Information',
                                              'Medical Records']},
 'date_detected': '2025-01-15',
 'date_publicly_disclosed': '2025-07-10',
 'date_resolved': '2025-06-11',
 'description': 'Heart Care Centers of Illinois (HCCI) reported a data breach '
                'stemming from a phishing attack that compromised an '
                'employee’s email account for 76 days from August 22 to '
                'November 6, 2024, before going undetected for 15 months. The '
                'breach exposed sensitive patient data, including names, '
                'Social Security numbers, medical records, and financial '
                'information. HCCI stated it had no evidence of data misuse '
                'but offered credit monitoring services to affected '
                'individuals.',
 'impact': {'brand_reputation_impact': 'Potential long-term reputational '
                                       'damage due to prolonged undetected '
                                       'breach',
            'data_compromised': 'Sensitive patient data, including names, '
                                'Social Security numbers, dates of birth, '
                                'driver’s license and state ID numbers, '
                                'payment card details, financial account '
                                'information, passport numbers, medical '
                                'treatment records, prescription histories, '
                                'and health insurance data',
            'identity_theft_risk': 'High (financial fraud, medical identity '
                                   'theft)',
            'legal_liabilities': 'Potential HIPAA violations and fines',
            'operational_impact': 'Delayed incident response and regulatory '
                                  'notifications',
            'payment_information_risk': 'High (payment card details exposed)',
            'systems_affected': 'Employee email account'},
 'initial_access_broker': {'entry_point': 'Employee email account'},
 'investigation_status': 'Completed',
 'lessons_learned': 'Significant gaps in phishing detection and incident '
                    'response, prolonged dwell time (15 months) increases risk '
                    'of data misuse and regulatory penalties',
 'post_incident_analysis': {'corrective_actions': 'Third-party forensic '
                                                  'investigation, data '
                                                  'analytics review, credit '
                                                  'monitoring services, and '
                                                  'potential improvements in '
                                                  'phishing detection and '
                                                  'response protocols',
                            'root_causes': 'Phishing attack leading to email '
                                           'account compromise, lack of timely '
                                           'detection, delayed incident '
                                           'response'},
 'recommendations': 'Improve phishing detection mechanisms, reduce incident '
                    'response times, enhance employee training on social '
                    'engineering attacks, and implement stricter monitoring of '
                    'email accounts',
 'references': [{'source': 'Cyber Incident Report'}],
 'regulatory_compliance': {'regulations_violated': 'HIPAA',
                           'regulatory_notifications': 'Reported to U.S. '
                                                       'Department of Health '
                                                       'and Human Services'},
 'response': {'communication_strategy': 'Delayed notifications to affected '
                                        'individuals (July 10, 2025)',
              'remediation_measures': 'Review of compromised email account, '
                                      'credit monitoring and identity '
                                      'restoration services offered',
              'third_party_assistance': 'Forensic specialists and data '
                                        'analytics firm'},
 'title': 'HCCI Discloses 15-Month Phishing Breach Exposing Sensitive Patient '
          'Data',
 'type': 'Phishing',
 'vulnerability_exploited': 'Employee email account compromise'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.