DisclosureLens
ILLINOISSocial EngineeringHealthcareHealthcarePhishingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedIdentity (basic)Government IDHealth (basic)Financial accountHighResolved

THE UNIVERSITY OF CHICAGO MEDICAL CENTER

bd_579dc4b435838e45 · schema v1 · pii pii-v1

Severity

High

Discovered

Mar 28, 2024

Filed

May 24, 2024

To disclose

Affected

10,332

Linked

4 filings

Confidence

97%
Full breach record for THE UNIVERSITY OF CHICAGO MEDICAL CENTER4 incidents on file

University of Chicago Medical Center (IL) reported to HHS on 2024-05-24 a Hacking/IT Incident (email phishing attack) affecting 10,332 individuals. Multiple employees were targeted in the phishing campaign. PHI exposed included names, dates of birth, Social Security numbers, passport numbers, driver's license/state ID numbers, financial information, diagnoses, medications, and health insurance/treatment information. Breached information located in Email. No business associate was involved. The CE offered credit monitoring and enhanced security safeguards; staff were retrained on email security.

HIPAA clock HHS report on time
unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.

Incident timeline

discovery → filing · 8 weeks / 57 days

Mar 28, 2024

Discovered

May 24, 2024

Filed

This filing is one of 4 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 4 states

View merged incident ↗
Massachusetts State AGMay 24 · first
Maine State AGMay 24 · first
Indiana State AGMay 24 · first
HHS OCRMay 24 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.