OSF HEALTHCARE SYSTEM
ent_019e2061bc3ad773a77eeaa64d7b1258
Disclosures
18
HHS OCR enforcement · State AG · HHS OCR · Leak Site · 5 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
94,171
nationwide · HHS OCR IL
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- OSF HEALTHCARE SYSTEM
- Normalized
- osf healthcare system— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300WHRBC55SQNFM42
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (18)newest first
- FEDERALHHS OCR enforcementas victim2026-07-29
HHS OCR settled a ransomware investigation with OSF Healthcare System regarding a 2021 breach affecting 53,907 patients. OSF agreed to pay $552,250 and implement a Corrective Action Plan addressing risk analysis, risk management, and notification failures.
- Illinois State AGas victim2024-10-01
OSF HEALTHCARE SYSTEM filed a data-breach notice with the Illinois Attorney General in October 2024 (case 24-10-054). The register records the breach as discovered on September 6, 2024. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2024-02-01
OSF HEALTHCARE SYSTEM filed a data-breach notice with the Illinois Attorney General in February 2024 (case 24-02-186). The register records the breach as discovered on December 5, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2023-01-01
OSF HEALTHCARE SYSTEM filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-334). The register records the breach as discovered on November 27, 2022. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2023-01-01
OSF HEALTHCARE SYSTEM filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-712). The register records the breach as discovered on September 19, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2023-01-01
OSF HEALTHCARE SYSTEM filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-207). The register records the breach as discovered on November 27, 2022. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2023-01-01
OSF HEALTHCARE SYSTEM filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-247). The register records the breach as discovered on March 5, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2023-01-01
OSF HEALTHCARE SYSTEM filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-061). The register records the breach as discovered on January 30, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2023-01-01
OSF HEALTHCARE SYSTEM filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-299). The register records the breach as discovered on March 5, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Montana State AGas victim2021-10-01
OSF HealthCare System notified patients of a security incident where unauthorized access occurred between March 7 and April 23, 2021. The breach affected patient data including names, SSNs, driver's licenses, and PHI at two Illinois medical centers. OSF engaged forensic investigators, notified law enforcement, and offered 12 months of Experian IdentityWorks.
- Massachusetts State AGas victim2021-10-01
OSF HealthCare System reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-10-01. 5 Massachusetts residents were affected. The report records the breach type as electronic.
- ILLINOISHHS OCRas victim2021-10-01
OSF HealthCare System reported to HHS on 2021-10-01 a Hacking/IT Incident affecting 53907 individuals. Breached information located on Network Server.
- GLOBALLeak Siteas victim2021-05-18
- Illinois State AGas victim2021-01-01
OSF HEALTHCARE SYSTEM filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-399). The register records the breach as discovered on April 23, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2021-01-01
OSF HEALTHCARE SYSTEM filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-485). The register records the breach as discovered on April 23, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Montana State AGas victim2020-10-19
OSF HealthCare System notified Montana residents of a third-party vendor breach involving Blackbaud, Inc. An unauthorized individual accessed Blackbaud's systems between Feb 7 and May 20, 2020, potentially obtaining backup databases containing patient PII and PHI. SSNs and financial data were encrypted and not accessed.
- ILLINOISHHS OCRas victim2020-10-19
OSF HealthCare System reported to HHS on 2020-10-19 a Hacking/IT Incident affecting 94,171 individuals. Breached information located on Network Server. A business associate experienced a ransomware attack affecting ePHI including names, addresses, phone numbers, email addresses, dates of birth, and treatment information.
- Illinois State AGas victim2020-01-01
OSF HELATH CARE SYSTEM filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-425). The register records the breach as discovered on February 7, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.