← Heart Care Centers of Illinois

2024 Heart Care Centers of Illinois — email account phishing (Aug–Nov); notices Jul 2026

2024 Unknown records affected Share on X

Data compromised

Per HCCI notice coverage: names, addresses, phone/fax, SSNs, dates of birth, driver’s license/state IDs, payment card information, financial account numbers, passport numbers, diagnosis/condition, prescriptions, treatment, health insurance, and provider information (varies)

Technical writeup

Verified healthcare email compromise — HIPAA Journal (July 23, 2026). Heart Care Centers of Illinois announced July 18, 2026 that patient PHI was exposed via an employee email account. While investigating an unsuccessful phishing attempt, HCCI identified historical suspicious activity on January 15, 2026; forensics confirmed unauthorized access between August 22 and November 6, 2024. Data review completed June 11, 2026. Affected individuals notified July 10, 2026 with credit monitoring offered. HHS OCR individual count not yet listed at indexing — recordsAffected set to 0 pending portal figure.

Root cause

Unauthorized access to an employee email account August 22–November 6, 2024, discovered during investigation of a later phishing attempt; patient notifications July 2026

References