Data leak

Illinois Department of Human Services Medicaid Data Exposure - 700K Residents

πŸ“… 2021-04-01
Primary Source β†—

Incident Details

The Illinois Department of Human Services (IDHS) exposed sensitive personal data of more than 700,000 state residents for approximately four years, from April 2021 to September 2025. On September 22, 2025, IDHS discovered that an internal resource planning/mapping website had been publicly accessible due to misconfigured privacy settings. Two groups were affected: (1) 672,616 Medicaid and Medicare Savings Program recipients β€” addresses, case numbers, and demographic data (names not included); (2) 32,401 Division of Rehabilitation Services recipients β€” names, addresses, case statuses, and service details. IDHS immediately secured the website, notified HHS Office for Civil Rights, and mailed notification letters. IDHS was unable to determine who viewed the maps; no evidence of misuse was identified.

Technical Details

Initial Attack Vector
Misconfigured internal mapping website β€” IDHS planning maps intended for internal use were inadvertently made accessible via the public internet; no malicious actor involved

Timeline

  1. 2021-04-01 Breach occurred
  2. 2025-09-22 Publicly disclosed
  3. 2026-01-08 Customers notified