A massive data breach at University of Iowa Health Care (UIHC) and UI Community HomeCare exposed the personal information of an estimated 211,000 patients, including Social Security numbers, birth dates, and insurance data. The breach, disclosed in late August, has already triggered at least eight class-action lawsuits against the institution. While UIHC has acknowledged the incident, it claims there is no current evidence that the compromised data has been misused. The breach raises significant concerns over patient privacy, potential identity theft, and long-term reputational damage to the healthcare provider. The scale of the exposure—affecting sensitive personally identifiable information (PII)—positions this as a high-stakes incident with possible financial and legal repercussions for the university and its affiliated healthcare services.
TPRM report: https://www.rankiteo.com/company/university-of-iowa-health-care
"id": "uni3594835100225",
"linkid": "university-of-iowa-health-care",
"type": "Breach",
"date": "8/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '211,000 patients',
'industry': 'Healthcare',
'location': 'Iowa City, IA, USA',
'name': 'University of Iowa Health Care',
'type': 'Healthcare Provider'},
{'customers_affected': 'Included in 211,000 patients',
'industry': 'Healthcare',
'location': 'Iowa City, IA, USA',
'name': 'UI Community HomeCare',
'type': 'Home Healthcare Provider'}],
'customer_advisories': 'Notifications sent to 211,000 affected patients in '
'late August 2023',
'data_breach': {'data_exfiltration': 'Likely (data accessed, misuse not '
'confirmed)',
'number_of_records_exposed': '211,000',
'personally_identifiable_information': ['social security '
'numbers',
'birth dates'],
'sensitivity_of_data': 'High (includes SSNs, birth dates, '
'insurance data)',
'type_of_data_compromised': ['personally identifiable '
'information (PII)',
'protected health information '
'(PHI)']},
'date_publicly_disclosed': '2023-08-28T00:00:00',
'description': 'A massive data breach at the University of Iowa Health Care '
'and UI Community HomeCare exposed personal information of an '
'estimated 211,000 patients, including social security '
'numbers, birth dates, and insurance data. At least eight '
'class-action lawsuits have been filed as a result. The '
'university has stated there is currently no indication that '
'the accessed data has been misused.',
'impact': {'brand_reputation_impact': 'Significant (lawsuits and public '
'disclosure)',
'customer_complaints': 'At least eight class-action lawsuits filed',
'data_compromised': ['social security numbers',
'birth dates',
'insurance data'],
'identity_theft_risk': 'High (SSNs and personal data exposed)',
'legal_liabilities': 'At least eight class-action lawsuits'},
'investigation_status': 'Ongoing (no confirmed misuse of data as of '
'disclosure)',
'references': [{'source': 'Local news report (Iowa City, IA)'},
{'source': 'Getty Images (photo credit)'}],
'regulatory_compliance': {'legal_actions': 'At least eight class-action '
'lawsuits filed'},
'response': {'communication_strategy': 'Patient notifications issued in late '
'August 2023'},
'title': 'University of Iowa Health Care Data Breach',
'type': 'Data Breach'}