The Southern Illinois Dermatology 2025 data breach was a confirmed health-data security event discovered when the dermatology provider learned that certain systems in its network environment had been affected by a cybersecurity incident. According to the official company notice, the event was identified on November 28, 2025, and the forensic review found that files may have been accessed and/or acquired by an unauthorized third party.
Southern Illinois Dermatology completed its extensive data review on March 4, 2026 and began notifications on April 2. The U.S. Department of Health and Human Services Office for Civil Rights lists the event as a Hacking/IT Incident affecting 160,312 people. LeakData imported no person rows, and importedRecordCount is zero.
How Was the Southern Illinois Dermatology Breach Confirmed?
The primary source is the “Notice Regarding Data Security Incident” PDF dated April 2, 2026 and published on the organization's own domain. It directly states the discovery date, investigation with third-party cybersecurity professionals, March 4 review result, confirmed data fields, individual notices, and post-incident security work.
The HHS OCR record classifies Southern Illinois Dermatology as an Illinois healthcare provider and reports 160,312 people, an April 2, 2026 submission date, a network-server location, and a hacking/IT incident type. A Massachusetts OCABR file also publishes the consumer notice as an official state record. The sources align on the entity, dates, and data classes.
What Happened on November 28, 2025?
Southern Illinois Dermatology learned on November 28 that certain systems within its network environment were affected by a cybersecurity incident and immediately began investigating the extent of the activity. The forensic work, supported by outside specialists experienced in such events, examined whether personal information had been accessed or acquired.
On March 4, the review concluded that files potentially accessed and/or acquired contained personal information or protected health information. The official PDF does not identify the actor, initial entry method, exact access window, or volume of files taken. LeakData does not add an unverified ransomware or threat-group attribution.
What Identity and Contact Information Was Affected?
The official list includes full names, addresses, dates of birth, Social security numbers, telephone numbers, and email addresses. Information combinations varied by person, so every field did not necessarily apply in the same way to all 160,312 people. These categories may increase the risk of targeted phishing and identity theft.
The source does not expressly list driver's licenses, passports, passwords, usernames, bank accounts, credit cards, or health-insurance numbers. Identification documents mentioned in general fraud and credit-freeze guidance are not confirmed incident fields. LeakData records only the categories directly named in the company's event description.
What Health Identifiers Were Involved?
The confirmed health-related fields are person numbers and medical-record numbers, and the company characterizes the files as containing protected health information. Even without detailed clinical notes, those identifiers may link an individual to the provider's patient or record system and raise a risk of fraudulent healthcare claims.
The official notice does not identify more granular medical fields such as diagnoses, treatments, prescriptions, laboratory results, images, dates of service, physician names, billing codes, or insurance policies. Advice to review explanation-of-benefits statements does not establish that those details were present in the incident. LeakData does not expand the scope.
How Did the Organization Respond?
Southern Illinois Dermatology engaged specialists, reviewed files that could contain personal information, began notifying affected individuals on April 2, and said it took measures to augment existing cybersecurity. It stated that it continually evaluates and modifies its practices to improve the security and privacy of personal information.
The official notice says there was no indication of identity theft or fraud resulting from the incident at the time of publication. Recipients received practical guidance on medical-identity theft, credit reports, fraud alerts, and security freezes. A dedicated response line was established at 1-833-997-6029 for questions about the event.
What Should Affected People Do?
Notice recipients should monitor credit reports, account activity, and health-insurance explanation-of-benefits statements for unfamiliar accounts, inquiries, or services. Because SSNs were involved, a credit freeze, fraud alert, and IRS Identity Protection PIN may be appropriate; unknown medical services should be verified with the provider and insurer.
SSNs, dates of birth, medical-record numbers, verification codes, or payments should not be provided in unexpected email, messages, or calls claiming to represent Southern Illinois Dermatology. Contact should be verified only through channels in the official notice. LeakData does not host, distribute, or make searchable the incident files, patient identifiers, or person records.