ILHackingHealthcareHealthcareCustomer Data InvolvedPHIHEALTH_BASICIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Iroquois Memorial Hospital
bd_35f9609ed9cd4e81 · schema v1 · pii pii-v1
Full breach record for Iroquois Memorial Hospital →Iroquois Memorial Hospital reported to HHS on 2026-01-09 a Hacking/IT Incident affecting 621 individuals. Breached information located on Network Server. The PHI involved demographic, clinical, and financial information. In response, the CE changed passwords, strengthened requirements, implemented safeguards, and provided credit monitoring.
Leak gap clock⏱ Leak >30d
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
⚠ No discovery dateThe OCR public portal omits the discovery date, so the 60-day notification clock cannot be evaluated from this source — only that the filing was submitted.
This filing is one of 2 about the same incident.View merged incident
A leak claim by pear about this victim predates this filing by 45 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_1721088b59788763Leak Sitepearfiled 2025-11-25(45d gap)Candidate
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jan 9, 2026
- Raw hash
- c852eeafac39194ac6d70eb9979fa788c1f48224ddbcbc609102e63ca8406295
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Iroquois Memorial Hospitalnorm: iroquois memorial hospital
- Domain
- iroquoismemorial.com
- Industry
- Health Care Services
Victim entity
- Name
- Iroquois Memorial Hospitalnorm: iroquois memorial hospital
- Domain
- iroquoismemorial.com
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- Jan 9, 2026
- Affected individuals
- 621
- Data types
- PHIHEALTH_BASICIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- Leak >30dHHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: Jan 9, 2026— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.