[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fBL9LbsHjxlJ_B90Bwq5HD7m3O0YkHlQS0MlSwtbveFs":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":17,"dataClasses":18,"description":21,"source":22,"isVerified":4,"isSpamList":23,"isSensitive":4,"severity":24,"processingStatus":25,"logoUrl":26,"contentUpdatedAt":16,"hasEnglishDescription":4},"6a66d59cd6e864c113ea10e2","SaintAnthonyHospital2025","Saint Anthony Hospital 2025 Data Breach","saint-anthony-hospital-2025","sahchicago.org",{"name":12,"sector":13,"country":14,"website":10},"Saint Anthony Hospital","Healthcare","United States","2025-02-27T00:00:00.000Z","2026-07-27T03:50:52.444Z",146108,[19,20],"Patient personal information","Protected health information","\u003Cp>\u003Cstrong>The Saint Anthony Hospital 2025 data breach\u003C\u002Fstrong> involved unauthorized access to two employee email accounts and associated unstructured files at the Chicago hospital. The hospital's official notice confirms that certain files and folders were accessed or acquired by an unauthorized party on or around February 27, 2025. The current record maintained by the US Department of Health and Human Services Office for Civil Rights shows that 146,108 people were affected.\u003C\u002Fp>\n\u003Cp>Saint Anthony said its electronic health records system was not affected, but the reviewed data contained patient personal information and protected health information. Because the March 2026 notice does not enumerate specific fields, LeakData limits dataClasses to those two confirmed high-level categories. No patient rows were imported into the system, and importedRecordCount is zero.\u003C\u002Fp>\n\u003Ch2>How Was the Saint Anthony Hospital Breach Confirmed?\u003C\u002Fh2>\n\u003Cp>The primary evidence is the hospital's Notice of Data Security Incident published on its own domain. It says an unauthorized party may have gained access to two employee email accounts and that the incident resulted in unauthorized access to or acquisition of certain unstructured files within the network. The organization also confirms that it contained the affected systems and investigated with third-party cybersecurity specialists.\u003C\u002Fp>\n\u003Cp>HHS OCR lists the event under a Healthcare Provider, classifies it as a Hacking\u002FIT Incident, and identifies Email as the location of the affected information. The federal total of 146,108 people supports the hospital's finding involving patient personal and health information with a regulatory record. HIPAA Journal independently compared the sources and corroborated the access date, review completion, notification timing, and updated scope.\u003C\u002Fp>\n\u003Ch2>What Was the Incident and Notification Timeline?\u003C\u002Fh2>\n\u003Cp>According to the official notice, the unstructured files and folders were accessed or acquired on or around February 27, 2025. The breachDate field uses February 27, the concrete date disclosed by the hospital. The public text does not identify the first day the actor entered the accounts, the total duration of access, or the date when the hospital initially detected the event, so this entry does not invent an earlier start date.\u003C\u002Fp>\n\u003Cp>Saint Anthony worked with specialists to identify the affected data and people, completing its file review around February 13, 2026. It then posted a substitute notice and began mailing notices to potentially affected individuals on March 6, 2026. The roughly one-year interval reflects the file-review and identity-matching process, not a claim that the attacker remained present for that entire period.\u003C\u002Fp>\n\u003Ch2>What Information Was Affected?\u003C\u002Fh2>\n\u003Cp>The March 2026 official statement says the affected unstructured data contained patient personal information and personal health information. It does not individually identify names, addresses, birth dates, Social Security numbers, diagnoses, prescriptions, or account numbers for this event. dataClasses therefore contains only Patient personal information and Protected health information.\u003C\u002Fp>\n\u003Cp>An older Saint Anthony public notice listed detailed fields, but HHS shows incidents with different dates and different affected-person counts, and automatically combining them would be unreliable. This entry is tied to the March 2026 notice covering 146,108 people and does not copy the earlier incident's field list into the newer scope. It also does not assume that every person had the same categories in their files.\u003C\u002Fp>\n\u003Ch2>Were Electronic Health Records Affected?\u003C\u002Fh2>\n\u003Cp>Saint Anthony's forensic investigation determined that its electronic health records system was not affected by this incident. That exclusion does not mean no health information was involved: patient personal and protected health information was found in unstructured files associated with the email environment. The distinction separates the central electronic-record platform from documents stored in email or network locations.\u003C\u002Fp>\n\u003Cp>LeakData consequently identifies Email as the affected system and does not imply that the entire clinical platform was compromised. Unstructured files could be attachments, scanned documents, or free-form records, but the sources do not specify their exact formats, so those possibilities are not added as facts. The documented exposure remains limited to the two categories that the hospital expressly confirmed.\u003C\u002Fp>\n\u003Ch2>How Should the 146,108-Person Total Be Interpreted?\u003C\u002Fh2>\n\u003Cp>The 146,108 values in pwnCount and totalRecords come from the current HHS OCR public record. It is the total number of affected people reported to the federal regulator, not the number of files, email accounts, or unique data fields. The two employee accounts describe the incident's access surface and must not be confused with the victim count.\u003C\u002Fp>\n\u003Cp>Because the HHS portal also contains a smaller Saint Anthony email incident reported in 2025, duplicate checking was not performed on the organization name alone. This record is distinguished by the February 27 access date, March 6, 2026 notification, and 146,108-person scope together. Separate federal rows are not added, and any unknown overlap between people in different events is not calculated.\u003C\u002Fp>\n\u003Ch2>What Should Affected People Do?\u003C\u002Fh2>\n\u003Cp>At the time of notice, the hospital said it was not aware of evidence that information had been misused or that identity theft or fraud had occurred. It nevertheless advised affected people to review financial account statements, credit reports, and health-insurance explanations of benefits regularly. An unfamiliar service, claim, or payment should be checked with the relevant provider or insurer through a known official channel.\u003C\u002Fp>\n\u003Cp>Unexpected links, payment requests, and identity-verification messages presented in Saint Anthony's name deserve particular scrutiny because incident context may support targeted phishing. Notice recipients should rely on the individual scope and official contact details in their mailed letter. LeakData does not publish or search stolen patient files; it provides only verified incident metadata, sources, and practical follow-up guidance.\u003C\u002Fp>","Confirmed unauthorized access to or acquisition of unstructured email-system files",false,"High","completed","\u002Fuploads\u002Flogo\u002Fsahchicago_org.png"]