University of Iowa Health Care, along with its affiliate UI Community HomeCare, experienced a cyberattack in July that resulted in a significant data breach. The incident exposed the personal and health information of over 211,000 individuals, including patients and potentially employees. The compromised data may include sensitive details such as medical records, personally identifiable information (PII), and other protected health information (PHI). The breach poses risks of identity theft, fraud, and unauthorized access to confidential medical histories. While the exact method of the attack (e.g., phishing, exploit of a vulnerability) was not specified, the scale and nature of the exposed data suggest severe operational, reputational, and legal repercussions for the healthcare provider. The breach also raises concerns about compliance with healthcare regulations like HIPAA, potentially leading to regulatory fines and loss of patient trust. No ransomware involvement was mentioned in the report.
TPRM report: https://www.rankiteo.com/company/university-of-iowa-health-care
"id": "uni3632336091125",
"linkid": "university-of-iowa-health-care",
"type": "Cyber Attack",
"date": "5/2025",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': '211,000',
'industry': 'Healthcare',
'location': 'Iowa, USA',
'name': 'University of Iowa Health Care',
'type': 'Healthcare Provider'},
{'customers_affected': 'Included in 211,000',
'industry': 'Healthcare',
'location': 'Iowa, USA',
'name': 'UI Community HomeCare',
'type': 'Healthcare Provider (Affiliate)'}],
'customer_advisories': 'Public notification issued to affected individuals',
'data_breach': {'number_of_records_exposed': '211,000',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Personal Information',
'Health Information']},
'description': 'University of Iowa Health Care and its affiliate, UI '
'Community HomeCare, disclosed a July cyberattack that exposed '
'the personal and health information of more than 211,000 '
'individuals.',
'impact': {'data_compromised': ['Personal Information', 'Health Information'],
'identity_theft_risk': 'High (Personal and Health Information '
'exposed)'},
'investigation_status': 'Disclosed (July 2024 incident, reported recently)',
'response': {'communication_strategy': 'Public Disclosure'},
'title': 'University of Iowa Health Care Data Breach',
'type': 'Data Breach'}