All Breaches
July 3, 2025 Verified Sensitive Record Healthcare

UI Community HomeCare and UI Health Care 2025 Data Breach

The UI Community HomeCare and UI Health Care 2025 data breach occurred when someone accessed the UI Community HomeCare computer system without permission on July 3, 2025. University of Iowa Health Care's official notice confirms that the actor viewed certain data files and took copies. HHS OCR divides the same incident between two affiliated-organization rows whose exact total is 210,904 people.

The contents varied by person and may have included names, dates of birth, addresses, phone numbers, medical record numbers, providers, dates of service, visit types, health insurance information, and Social security numbers. The electronic health record system was not affected. LeakData does not host acquired patient or employee rows, and importedRecordCount is zero.

How Was the UI Community HomeCare Data Breach Confirmed?

The primary source is University of Iowa Health Care's public notice dated August 29, 2025. It says the UI Community HomeCare system was accessed without permission and expressly states that the cybercriminal could see files and take copies. That wording establishes confirmed acquisition rather than merely the possibility that information was accessed.

The federal HHS OCR breach portal lists 109,029 people for University of Iowa Community Home Care and 101,875 for University of Iowa Health Care. Both rows have the same report date, incident type, and information location: August 29, 2025, Hacking/IT Incident, and Network Server. The HIPAA Journal independently reviewed the announcement and reported the single event as affecting about 211,000 people.

What Happened on July 3, 2025?

UI Community HomeCare identified on July 3 that someone had accessed its computer system without authorization. The organization shut down servers, engaged cybersecurity experts, and safely restored systems within one business day. The breachDate field uses July 3, the confirmed access date disclosed in the public notice.

The forensic review found that the actor not only viewed certain files but also took copies. UI Community HomeCare and UI Health Care had separate operating systems, electronic health records, and information technology services, but their historical relationship involved shared patients, employees, and data files. A group of UI Health Care files stored in the affiliate's environment was therefore involved.

What Information Was Affected?

The official notice lists names, dates of birth, addresses, phone numbers, medical record numbers, providers, dates of service, health insurance information, Social security numbers, and visit types as possible fields. They are recorded under the broader personal-information and protected-health-information categories. The combination was not the same for every person, so no field is attributed to the entire population.

The notice's FAQ says there was no indication that Social security numbers were included for certain addressed recipient groups, while the main public notice lists the field among the possible elements. LeakData retains it as a data class because the principal notice expressly supports it but does not assign it to every affected person. Undisclosed fields such as diagnoses, prescriptions, payment cards, or passwords are not inferred.

Was the Electronic Health Record Affected?

The official investigation confirmed that there was no unauthorized access to the UI Health Care electronic health record system. This limitation does not remove the incident's significance because identity, contact, insurance, and care-relationship data held in shared files was still copied. The entry describes only the confirmed file scope and does not claim that the full clinical system was compromised.

The organization contacted law enforcement, implemented new monitoring tools, updated firmware, changed passwords, and removed files from affected hardware. It said no indication of misuse had been identified when notices were issued. That finding does not reverse the confirmed acquisition and cannot eliminate the future risk of identity, insurance, or healthcare fraud.

How Was the 210,904-Person Scope Calculated?

The official notice rounds the combined population to approximately 211,000 people. HHS OCR publishes the same July 3 event in two affiliated-entity rows: 109,029 and 101,875. LeakData adds those exact federal values and uses 210,904 for pwnCount and totalRecords, which is consistent with the official rounded total.

The two HHS rows are not presented as separate attacks because the date, infrastructure, notification day, and official narrative all describe one event. Public materials do not say whether any individuals overlap between the two federal rows; because HHS reports the populations under separate entities, their sum is the strongest available exact figure. The method and uncertainty are preserved in the source notes.

What Should Affected People Do?

UI Health Care and UI Community HomeCare mailed letters to affected individuals on August 29, 2025. The organization said it was not offering complimentary credit monitoring because it had found no indication of misuse at notification. Recipients should use the fields identified in their own letter and regularly review account statements, credit reports, and health-insurance explanations of benefits.

If an unfamiliar medical service, insurance claim, new credit account, or identity-verification message appears, contact the relevant organization through a known official channel. Be especially cautious with unexpected calls or links that invoke the names of the affected institutions. LeakData provides no downloadable patient data; it publishes verified incident metadata and practical follow-up guidance.

210.9 Thousand
Affected Accounts
12
Data Types
High
Severity
Yes
Verification

Exposed Data Types

12
Personal information
Protected health information
Names
Dates of birth
Physical addresses
Phone numbers
Medical record numbers
Healthcare providers
Dates of service
Visit types
Health insurance information
Social security numbers

Additional Information

Added DateJuly 27, 2026
Breach DateJuly 3, 2025
Domainuihc.org
SourceOfficial notice confirming unauthorized viewing and copying of files
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information