UI Community HomeCare, a healthcare provider affiliated with University of Iowa Health Care, suffered a major data breach in July 2025. An unauthorized cybercriminal accessed and copied files containing highly sensitive personal and protected health information (PHI) of **211,000 patients**, including names, dates of birth, addresses, phone numbers, Social Security numbers, medical record numbers, provider details, dates of service, health insurance data, and visit types. The breach affected both UI Community HomeCare customers and a subset of University of Iowa Health Care patients. The incident was severe due to the scale of compromised data and the confirmed exfiltration of records. Notifications were sent to victims in late August 2025, alongside regulatory disclosures and the establishment of a dedicated support hotline. The breach poses significant risks of identity theft, financial fraud, and long-term reputational damage to the organization.
Source: https://www.claimdepot.com/data-breach/ui-community-homecare-2025
TPRM report: https://www.rankiteo.com/company/university-of-iowa-health-care
"id": "uni1461514090425",
"linkid": "university-of-iowa-health-care",
"type": "Breach",
"date": "7/2025",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': '211,000',
'industry': 'Healthcare (Home Infusion and Medical '
'Equipment Services)',
'location': 'Affiliated with University of Iowa Health '
'Care (USA)',
'name': 'UI Community HomeCare',
'type': 'Healthcare Provider'},
{'customers_affected': 'Subset of 211,000 (group of '
'patients)',
'industry': 'Healthcare',
'location': 'USA',
'name': 'University of Iowa Health Care',
'type': 'Healthcare System'}],
'customer_advisories': ['Review breach notices carefully',
'Monitor for identity theft',
'Use credit freezes/fraud alerts',
'Avoid sharing personal info in response to '
'unsolicited contacts'],
'data_breach': {'data_exfiltration': True,
'number_of_records_exposed': '211,000',
'personally_identifiable_information': True,
'sensitivity_of_data': 'High (includes SSNs, medical records, '
'and health insurance info)',
'type_of_data_compromised': ['Personal data',
'Protected Health Information '
'(PHI)']},
'date_detected': '2025-07-03',
'date_publicly_disclosed': '2025-08-29',
'description': 'UI Community HomeCare, a provider of home infusion and '
'medical equipment services affiliated with University of Iowa '
'Health Care, experienced a major data breach impacting '
'211,000 patients. On July 3, 2025, the organization '
'discovered that a cybercriminal accessed its computer system. '
'An investigation determined that files containing personal '
'and protected health data were viewed and copied. Exposed '
'information included names, dates of birth, addresses, phone '
'numbers, Social Security numbers, medical record numbers, '
'providers, dates of service, health insurance information, '
'and types of visits.',
'impact': {'brand_reputation_impact': 'Severe (due to scale and sensitivity '
'of data compromised)',
'data_compromised': ['Names',
'Dates of birth',
'Addresses',
'Phone numbers',
'Social Security numbers',
'Medical record numbers',
'Providers',
'Dates of service',
'Health insurance information',
'Types of visits'],
'identity_theft_risk': 'High (due to exposure of SSNs and '
'personal/health data)',
'systems_affected': ['Computer system (files containing personal '
'and protected health data)']},
'initial_access_broker': {'high_value_targets': ['Personal and protected '
'health data']},
'investigation_status': 'Completed (determined files were viewed and copied)',
'ransomware': {'data_exfiltration': True},
'recommendations': ['Monitor financial accounts and credit reports for signs '
'of identity theft',
'Consider placing fraud alerts or credit freezes with '
'major credit bureaus',
'Be cautious of unsolicited emails/phone calls requesting '
'personal information'],
'references': [{'source': 'UI Community HomeCare Data Privacy Event Notice'},
{'source': 'UI Community HomeCare Website'}],
'regulatory_compliance': {'regulatory_notifications': ['State disclosures',
'Federal disclosures']},
'response': {'communication_strategy': ['Mail notifications to affected '
'patients (sent on 2025-08-29)',
'Data privacy event notice posted on '
'websites',
'Dedicated toll-free hotline '
'(833-745-0871, available Mon-Fri 8 '
'AM–8 PM CT)'],
'incident_response_plan_activated': True},
'stakeholder_advisories': ['Mail notifications',
'Website notices',
'Toll-free hotline support'],
'threat_actor': 'Unauthorized individual/cybercriminal',
'title': 'UI Community HomeCare Data Breach',
'type': 'Data Breach'}