Illinois Department of Healthcare and Family Services
ent_8788124bb887c9a7a198ef40
Disclosures
8
State AG · HHS OCR · 1 jurisdiction
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
8,848
nationwide · HHS OCR IL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Illinois Department of Healthcare and Family Services
- Normalized
- illinois department of healthcare and family— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (8)newest first
- Illinois State AGas victim2026-03-01
ILLINOIS DEPARTMENT OF HEALTHCARE AND FAMILY SERVICES filed a data-breach notice with the Illinois Attorney General in March 2026 (case 26-03-1059). The register records the breach as discovered on December 10, 2025. Personal information types reported: drivers license, medical information, ssn. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2025-06-01
ILLINOIS DEPARTMENT OF HEALTHCARE AND FAMILY SERVICES filed a data-breach notice with the Illinois Attorney General in June 2025 (case 25-06-218). The register records the breach as discovered on February 11, 2025. Personal information types reported: drivers license, financial account number, medical information, ssn. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2022-01-01
ILLINOIS DEPT. OF HEALTHCARE & FAMILY SERVICES filed a data-breach notice with the Illinois Attorney General during 2022 (case 2022-159). The register records the breach as discovered on April 19, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2022-01-01
ILLINOIS DEPT. OF HEALTHCARE & FAMILY SERVICES filed a data-breach notice with the Illinois Attorney General during 2022 (case 2022-145). The register records the breach as discovered on December 30, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2022-01-01
ILLINOIS DEPT. OF HEALTHCARE & FAMILY SERVICES filed a data-breach notice with the Illinois Attorney General during 2022 (case 2022-236). The register records the breach as discovered on January 27, 2022. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- ILLINOISHHS OCRas victim2021-03-22
Illinois Department of Healthcare and Family Services (IL Health Plan) reported to HHS on 2021-03-22 an Unauthorized Access/Disclosure affecting 8,848 individuals. An employee mailed PHI to the wrong recipients. Breached information on Paper/Films included names, dates of birth, addresses, SSNs, financial information, diagnoses, conditions, citizenship status, and other treatment information. The CE notified HHS, individuals, and media, and implemented additional administrative and technical safeguards. OCR provided technical assistance.
- ILLINOISHHS OCRas victim2018-04-26
Illinois Department of Healthcare and Family Services reported to HHS on 2018-04-26 a Unauthorized Access/Disclosure affecting 8000 individuals. Breached information located on Paper/Films. A state employee inadvertently changed client addresses and mailed PHI to wrong recipients. The CE implemented additional administrative safeguards.
- ILLINOISHHS OCRas victim2013-07-15
Illinois Department of Healthcare and Family Services reported to HHS on 2013-07-15 a Hacking/IT Incident (computer program error causing misdelivery) affecting 3,133 individuals. Business associate Family Health Network mailed member identification cards to wrong addresses due to a computer program error. PHI exposed included names, dates of birth, and State-issued Medicaid numbers. The BA corrected the conversion process, reviewed privacy policies, and notified HHS, the CE, affected individuals, and the media. OCR obtained documented assurances of corrective action.