All Breaches
August 22, 2024 Verified Sensitive Record Healthcare

Heart Care Centers of Illinois 2024 Data Breach

The Heart Care Centers of Illinois 2024 data breach involved a successful phishing attack that gave unauthorized access to an employee email account from August 22 through November 6, 2024. HCCI discovered the historical suspicious activity on January 15, 2026, while investigating a separate, unsuccessful phishing attempt.

An outside forensic investigation confirmed the historical access, and analysis of data in the affected mailbox finished June 11, 2026. Names, addresses, SSNs, birth dates, government IDs, financial accounts, payment cards, passports, and health information may have been accessible. The organization did not disclose a total affected population.

How Was the Heart Care Centers of Illinois Breach Confirmed?

The primary source is HCCI's July 2026 incident notice on its own domain. It directly states the discovery date, email-account access period, review-completion date, possible data fields, the start of notification letters on July 10, and the dedicated assistance line at 888-616-9388.

The organization's release distributed through Business Wire confirms its public announcement. ClaimDepot's summary compares the notice and public filings and reports the same timeline and data categories. The sources agree that this is a distinct HCCI incident; LeakData does not add a dark-web claim or unsupported threat-actor attribution.

What Happened From August 22 Through November 6, 2024?

While examining an unsuccessful phishing attempt on January 15, 2026, HCCI found older suspicious activity tied to an employee account. Third-party specialists found evidence that a successful historical phishing attack had provided access to that account from August 22, 2024, until November 6, 2024.

The public notice does not describe the phishing message, how the employee was persuaded, the status of multifactor authentication, or the actor's identity. The incident is associated with one employee email account; the sources do not confirm compromise of other systems, a ransom demand, or public release of the information.

What Identity and Contact Information Was Involved?

Possible personal fields were names, mailing addresses, Social security numbers, dates of birth, driver's-license or state-identification numbers, passport numbers, telephone numbers, and fax numbers. The notice does not say every person had every field involved; actual scope depends on the data elements listed in each recipient's letter.

The combination of an SSN, birth date, and government ID can increase risks of new-account fraud, impersonation, and tax fraud. A phone number, address, or fax number is not an authentication secret by itself, but it can help an attacker create a convincing institutional message. LeakData does not list undisclosed fields such as email passwords or biometrics.

What Risks Come From Financial and Health Data?

Potential financial fields were payment-card information and financial-account numbers. Health-related fields may have included treatment, condition and diagnosis details, prescription information, health-insurance information, and provider information. The notice does not confirm a bank PIN, card security code, online-banking password, or a particular diagnosis for every person.

These categories can provide context for fake billing or reimbursement requests, healthcare-provider impersonation, and targeted financial messages. Even when a message contains a real physician, institution, or account detail, recipients should avoid its inbound link. Open the patient portal, insurer, and financial institution independently through official channels.

How Many People Were Affected and How Did HCCI Respond?

HCCI did not publish a nationwide total or a precise state population. Accordingly, pwnCount and totalRecords are null and affectedCountStatus is “not_disclosed”; LeakData does not use zero. This prevents an incorrect “nobody was affected” conclusion while reflecting that the existence of people requiring notification is confirmed.

The organization worked with outside forensic specialists to investigate and remediate the event, reviewed existing policies and safeguards, and began sending letters to potentially affected people July 10, 2026. Eligible recipients received complimentary credit monitoring and identity-restoration services through Epiq, with an enrollment deadline of October 31, 2026.

What Should Potentially Affected People Do?

Recipients should use the actual data list in their own letter. If an SSN or identification number was involved, consider freezes at all three credit bureaus and a fraud alert; for financial information, monitor transactions, new payees, and contact-detail changes. Promptly report an unfamiliar transaction or record through an official channel.

People whose health or insurance information was present should review explanation-of-benefits statements, patient portals, and unfamiliar provider records. In unexpected calls using the HCCI or Epiq name, do not disclose a password, full SSN, card security code, or one-time code. Independently open HCCI's official site or call 888-616-9388 to verify.

0
Affected Accounts
15
Data Types
Low
Severity
Yes
Verification

Exposed Data Types

15
Personal information
First and last names
Mailing addresses
Social security numbers
Dates of birth
Driver's license numbers
State identification numbers
Passport numbers
Telephone and fax numbers
Payment card information
Financial account numbers
Medical information
Prescription information
Health insurance information
Healthcare provider information

Additional Information

Added DateJuly 27, 2026
Breach DateAugust 22, 2024
Domainheartcc.com
SourceOfficial healthcare-provider notice confirming historical phishing and unauthorized employee email-account access
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information