All Breaches
September 22, 2025 Verified Sensitive Record Government

Illinois DHS Public Maps 2025 Data Breach

The Illinois DHS Public Maps 2025 data breach occurred when internal planning maps created by the Illinois Department of Human Services were viewable on a public mapping website because of incorrect privacy settings. The agency discovered the issue on September 22, 2025, and confirmed that the maps contained personal or protected health information belonging to hundreds of thousands of Medicaid, Medicare Savings Program, and rehabilitation-services recipients.

The IDHS notice identifies approximately 672,616 Medicaid and Medicare Savings Program recipients and approximately 32,401 Division of Rehabilitation Services customers. The two published category counts sum to 705,017, which this record uses for pwnCount and totalRecords. Because the agency described both values as approximate and did not separately discuss possible overlap, the result should not be read as an exact, deduplicated census of unique people.

How Was the Incident Confirmed?

IDHS's official HIPAA media notice dated January 2, 2026 directly explains that incorrect privacy settings made the maps public, lists the involved fields, and identifies the two affected groups. The agency said it was sending legally required notices to individuals and applicable regulators. That disclosure confirms the event as an exposure of protected health information requiring notification, rather than merely an internal configuration observation.

BleepingComputer and The HIPAA Journal independently reviewed the official announcement and corroborated the exposure periods, category counts, data types, and restriction of access. The HIPAA Journal also reported notification to the HHS Office for Civil Rights. LeakData records findings shared by these sources; because the platform could not identify who viewed the maps, it does not claim without evidence that an attacker downloaded or misused the information.

Why Were the Maps Publicly Accessible?

The maps were created by the Bureau of Planning and Evaluation within the IDHS Division of Family and Community Services to support resource-allocation decisions. They helped with internal planning questions such as where new local offices should open and were intended only for departmental use. Incorrect privacy controls on the mapping platform made the linked material viewable on the internet by people who were not authorized IDHS users.

This was not described as ransomware, phishing, or a confirmed account takeover; the underlying cause was an access-setting error on a public platform. The agency said the mapping website could not determine who viewed the maps. Public exposure is therefore a confirmed data incident, but no specific attacker, volume of downloaded files, or chain of malicious use belongs in the verified scope.

Which Groups and Data Were Affected?

For the Division of Rehabilitation Services group, data associated with approximately 32,401 customers was accessible from April 2021 through September 2025. The maps included names, addresses, case numbers, case status, referral-source information, region and office information, and status as a DRS recipient. This was the smaller category in which the official notice explicitly says names were included.

For approximately 672,616 Medicaid and Medicare Savings Program recipients, information was public from January 2022 through September 2025. The exposed fields included addresses, case numbers, demographic information, and names of medical-assistance plans such as Medicaid or Medicare; IDHS specifically said recipient names were not included in those maps. A plan name combined with case context is protected health information, making the event sensitive.

How Did IDHS Contain the Exposure?

After discovery on September 22, IDHS began changing the privacy settings on all relevant maps and completed restrictions to authorized employees by September 26. It then performed a comprehensive review to identify the content in each map and assess duties under state and federal privacy laws. The timeline establishes a four-day response window between discovery and completion of access restrictions across the maps.

The agency also implemented a Secure Map Policy that prohibits customer-level data from being uploaded, entered, or stored on public mapping websites. Access to customer-related maps is now restricted by role, and controls were added to prevent identifiable customer information from being placed on public platforms. These are confirmed corrective actions, but they cannot retrospectively identify everyone who may have viewed the information.

What Should Affected People Do?

IDHS said it would send legally required notices and include toll-free telephone numbers for additional information. Recipients should review the group and data fields identified in their letter, verify unfamiliar benefit-program or case correspondence, and use official contact numbers when speaking with the agency. Targeted phishing messages may appear more credible when they mention a health plan, assistance program, or case number.

The agency said it was unaware of actual or attempted misuse of personal information connected to the incident. That finding does not eliminate risk; it means no misuse had been identified by the disclosure date. U.S. consumers can monitor credit reports, consider free fraud alerts or security freezes, and report suspicious healthcare or public-benefit communications to the relevant agency.

How Should This LeakData Record Be Read?

The 705,017 value is the arithmetic sum of the approximately 672,616 and 32,401 category counts in the official release. Sources publish them as affected groups, but IDHS did not explain a final deduplication method or whether any person could appear in both categories. The record therefore presents the number as a documented category total and impact estimate, not as a precise dataset of individually verified identities.

importedRecordCount is zero, and LeakData stores no names, addresses, case numbers, demographics, or health-plan information from the event. This is a real, agency-reported exposure of protected health information, but there is no confirmation that a specific attacker downloaded or used it. If HHS or IDHS publishes a final deduplicated count, pwnCount, totalRecords, and the data classes can be updated from that primary evidence.

705 Thousand
Affected Accounts
10
Data Types
High
Severity
Yes
Verification

Exposed Data Types

10
Names
Physical addresses
Case numbers
Case statuses
Referral sources
Regional and office information
Recipient status
Demographic information
Medical assistance plan names
Protected health information

Additional Information

Added DateJuly 27, 2026
Breach DateSeptember 22, 2025
Domaindhs.state.il.us
SourceIncorrect privacy settings on public planning maps
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information