Heart Care Centers of Illinois: Heart Care Centers of Illinois Data Breach Compromises PHI and PII

Heart Care Centers of Illinois: Heart Care Centers of Illinois Data Breach Compromises PHI and PII

Heart Care Centers of Illinois Discloses 2024 Data Breach Following Phishing Attack

Heart Care Centers of Illinois, a Chicago-area cardiovascular medical group, revealed a data breach stemming from a phishing attack that compromised an employee’s email account between August 22 and November 6, 2024. The breach was discovered on January 15, 2026, during an investigation into a separate, unsuccessful phishing attempt, which uncovered prior unauthorized access to the account.

A forensic review, completed on June 11, 2026, confirmed that sensitive patient data may have been exposed. The compromised information varied by individual but included personally identifiable information (PII) such as names, Social Security numbers, dates of birth, and driver’s license numbers as well as protected health information (PHI), including medical treatment details, prescription records, health insurance data, and financial account numbers.

Notification letters were mailed to affected individuals beginning July 10, 2026, with the incident also publicly disclosed via Business Wire. While the total number of impacted individuals remains undisclosed, Heart Care Centers of Illinois is offering complimentary credit monitoring and identity restoration services through Epiq, available until October 31, 2026. A dedicated assistance line (888-616-9388) was established for inquiries.

Source: https://www.claimdepot.com/data-breach/heart-care-centers-of-illinois-2026

Heartland Health Centers cybersecurity rating report: https://www.rankiteo.com/company/heartland-health-centers

"id": "HEA1784566790",
"linkid": "heartland-health-centers",
"type": "Breach",
"date": "1/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Healthcare',
                        'location': 'Chicago, Illinois, USA',
                        'name': 'Heart Care Centers of Illinois',
                        'type': 'Healthcare Provider'}],
 'attack_vector': 'Phishing',
 'customer_advisories': 'Complimentary credit monitoring and identity '
                        'restoration services offered through Epiq until '
                        'October 31, 2026; dedicated assistance line '
                        '(888-616-9388) established',
 'data_breach': {'personally_identifiable_information': ['Names',
                                                         'Social Security '
                                                         'numbers',
                                                         'Dates of birth',
                                                         'Driver’s license '
                                                         'numbers',
                                                         'Medical treatment '
                                                         'details',
                                                         'Prescription records',
                                                         'Health insurance '
                                                         'data',
                                                         'Financial account '
                                                         'numbers'],
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Personally identifiable '
                                              'information (PII)',
                                              'Protected health information '
                                              '(PHI)']},
 'date_detected': '2026-01-15',
 'date_publicly_disclosed': '2026-07-10',
 'description': 'Heart Care Centers of Illinois disclosed a data breach '
                'stemming from a phishing attack that compromised an '
                'employee’s email account, leading to the exposure of '
                'sensitive patient data including PII and PHI.',
 'impact': {'data_compromised': 'Personally identifiable information (PII) and '
                                'protected health information (PHI)',
            'identity_theft_risk': 'High',
            'payment_information_risk': 'High',
            'systems_affected': 'Employee email account'},
 'investigation_status': 'Completed',
 'post_incident_analysis': {'root_causes': 'Phishing attack leading to '
                                           'unauthorized access to an employee '
                                           'email account'},
 'references': [{'source': 'Business Wire'}],
 'regulatory_compliance': {'regulations_violated': ['HIPAA']},
 'response': {'communication_strategy': 'Notification letters mailed to '
                                        'affected individuals; public '
                                        'disclosure via Business Wire',
              'remediation_measures': 'Credit monitoring and identity '
                                      'restoration services offered',
              'third_party_assistance': 'Forensic review conducted'},
 'title': 'Heart Care Centers of Illinois Data Breach Following Phishing '
          'Attack',
 'type': 'Data Breach',
 'vulnerability_exploited': 'Compromised employee email account'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.