The Meridian Health Plan of Illinois 2026 data breach resulted from some providers being given improper access to an online system, allowing someone without authorization to potentially view or download member information. Meridian learned of the issue April 28, 2026, disabled the accounts involved, opened an investigation, and notified law enforcement.
Information varied by person but could include member names, Meridian Member id numbers, dates of birth, contact information, and limited eligibility or claims-related details. The U.S. Department of Health and Human Services record reports 21,027 people. LeakData uses that figure for pwnCount and totalRecords; importedRecordCount is zero.
How Was the Meridian Health Plan Breach Confirmed?
The primary source is Meridian Health Plan of Illinois' “Provider Portal Incident Notice” published June 17, 2026 on its own domain. The organization directly explains the access-authorization issue, possible viewing or downloading, data categories, account shutdown, law-enforcement notification, added security and training, and the Member Services number.
The HHS Office for Civil Rights breach portal provides a healthcare-data notification affecting 21,027 people. Claim Depot connects the official announcement with the HHS record and summarizes the organization, discovery date, provider portal, population, and data classes. The sources align on the event type, core fields, and affected population.
What Happened in the Provider Portal?
On April 28, Meridian learned of an incident involving how some providers were given access to its online system. As a result, someone who should not have had access may have viewed or downloaded certain member information. Once it found the issue, the organization disabled the accounts involved, opened an investigation, and informed law enforcement.
The public page does not say when the first improper account was created, the exact start and end times, how many provider accounts were involved, the person's identity, or which records were definitely downloaded. “May have viewed or downloaded” warrants treating possible acquisition seriously but does not prove that every field for all 21,027 members was copied.
What Identity and Contact Information Was Affected?
The official notice says member names, dates of birth, and contact information may have been affected. It does not separately explain whether the contact category includes mailing addresses, emails, or telephone numbers; LeakData does not add those subfields as individually confirmed classes. Because information varied by member, the same combination should not be assumed for everyone.
A name, birth date, and health-plan context can make targeted phishing, fraudulent plan updates, or provider impersonation more convincing. Members should not follow links or provide passwords or one-time codes in unexpected messages claiming to come from Meridian. Requests to change contact details should be verified through the official member portal or the number on the member card.
What Is the Risk From a Member ID Number?
A Meridian Member ID number is one of the potentially affected fields. It is not a Social Security number, but links a person to a particular health plan and can provide context for fraudulent member support, provider inquiries, or insurance transactions. The public notice does not list SSNs, driver's licenses, payment cards, bank accounts, passwords, or government IDs as event data.
LeakData does not convert examples in general identity-theft guidance into incident fields. Members should share a plan ID only with verified providers and should not read the full number during an unexpected call. Claims about a replacement card, plan change, or verification request should be checked through an official Meridian channel, and unfamiliar online-account changes should be reported promptly.
How Were Eligibility and Claims Details Affected?
The official page says limited eligibility or claims-related details may have been viewed or downloaded. These fields can expose limited health context about plan coverage, the existence of a claim, or a provider transaction. The organization does not separately confirm complete medical records, diagnoses, treatment, prescriptions, medical-record numbers, service dates, or claim amounts.
Members should review statements from Meridian and online claim history for services they did not receive. An unfamiliar service or claim should be reported directly to Member Services. The word “limited” indicates constrained scope; LeakData does not expand it into access to a complete clinical file or all provider records.
How Many People Were Affected and How Did Meridian Respond?
The HHS breach portal reports 21,027 affected people for Meridian Health Plan of Illinois. That regulatory figure is used for pwnCount and totalRecords. LeakData did not obtain member rows, portal content, or claim records, so importedRecordCount is zero. The organization said it had found no signs of misuse or fraud at the notification date.
Affected accounts were disabled, while the plan added security, reviewed account-approval processes, provided more staff training, and continued monitoring for misuse. Members may call 866-606-3700 weekdays from 8 a.m. to 5 p.m. The time-bound “no signs” finding does not eliminate future risk, so statements and claims should be monitored. LeakData does not host incident files or member records.