What You Need to Know about the Illinois and Texas Healthcare Data Breaches

  • Published: May 06, 2026
  • Last Updated: May 06, 2026

Three prominent healthcare organizations in the United States have officially disclosed major data breaches that have compromised the personal and medical information of about 600,000 people. The affected organizations were Southern Illinois Dermatology and Saint Anthony Hospital in Illinois and the North Texas Behavioral Health Authority (NTBHA) in Texas. Saint Anthony is a renowned nonprofit acute care hospital serving Chicago’s West Side, Southern Illinois Dermatology is a key regional skincare provider in Salem, and the NTBHA provides vital mental health and substance abuse services across North Texas. 

The largest of three incidents involved the NTBHA affecting 285,086 individuals. The organization identified unauthorized activity within its computer systems in late 2025, and an investigation confirmed that an unauthorized third party accessed its network, during which time files containing patient information may have been viewed or acquired. The compromised data may have included names, addresses, Social Security numbers, driver's license numbers, medical information, health insurance information, and dates of birth.

The second incident involved Southern Illinois Dermatology, which confirmed that certain systems in its network environment were affected by a cybersecurity incident. A notice from the organization stated that files potentially accessed or acquired by an unauthorized third party contained personal information or protected health information. The exposed information affected a total of 160,312 people and may have included names, addresses, dates of birth, Social Security numbers, telephone numbers, email addresses, person numbers, and medical record numbers.

The third incident involved the Saint Anthony Hospital in Chicago. The hospital stated that an unauthorized party may have accessed two employee email accounts and certain unstructured files within its network. Saint Anthony said its electronic health records system was not affected, but certain files and folders were accessed or acquired. Such files and folders were believed to contain personal and health information of about 146,108 patients.

When Were the Illinois and Texas Healthcare Data Breaches?

According to the NTBHA's investigation, the authorized network access occurred between October 13 and October 15, 2025. However, on January 7, 2026, the organization determined that affected files may have contained personal information and began notifying affected individuals on March 6, 2026.

The cybersecurity attack on the Southern Illinois Dermatology network was identified on November 28, 2025. After forensic investigation and data review, the provider determined on March 4, 2026, that potentially accessed or acquired files contained personal information or protected health information. The organization began notifying affected individuals on April 2, 2026.

The unauthorized access to files and folders on Saint Anthony Hospital's network occurred on February 27, 2025. The organization's review of the incident concluded around February 13, 2026, while the hospital mailed notices to potentially affected individuals on March 6, 2026.

How to Check if Your Data Was Breached

Persons affected by these breaches have been sent notices by the relevant healthcare organization in accordance with the HIPAA breach notification rule. All three companies commenced issuing notices to affected individuals between March and April, 2026. Therefore, if you believe that your data may have been breached, watch your mail for a notification letter.

However, if you have received care from any of the three organizations and have not received a notification, you may contact the organization directly through its official response line or official website. Southern Illinois Dermatology may be contacted on a dedicated toll-free response line at 1-833-997-6029, while Saint Anthony's Hospital is available at 1-833-844-5403. 

You may also use services like HaveIBeenPwned.com and AmIBreached.com to check whether your email address appears in known data breaches, although healthcare-specific information may not be captured by such services.

What to Do If Your Data Was Breached

If your data was breached in any of the incidents, you should start by reviewing any specific steps highlighted in the notice sent by the healthcare organization. This is because the exact risk you are exposed to depends on which organization held your data and the specific data elements leaked. For instance, Saint Anthony advised affected patients and families to review explanation-of-benefits statements and follow up on unfamiliar items.

You should also monitor financial accounts, credit reports, medical bills, insurance statements, and patient portal activity. North Texas Behavioral Health Authority also advised affected individuals to review credit reports and medical information for unfamiliar activity.

It is important for affected persons to be cautious of phishing attempts. This is because a criminal may use exposed names, healthcare provider details, email addresses, medical record numbers, or dates of birth to make scam emails or phone calls appear legitimate. Do not click unexpected links, download attachments, or provide personal details unless you verify the request through an official phone number or website.

Are There Any Lawsuits Because of the Illinois and Texas Healthcare Data Breaches?

While no class action lawsuits have been certified, several law firms have opened investigations into the breaches and are considering filing them.

  • Southern Illinois Dermatology breach: Multiple law firms, including Edelson Lechtzin LLP, Schubert Jonckheer & Kolbe LLP, and attorneys working with ClassAction.org, are investigating the cybersecurity incident. The investigation is exploring whether the delayed notification may have violated state and federal laws.
  • Saint Anthony Hospital breach: Although the hospital has faced prior class action litigation, including a $1.46 million settlement over biometric data privacy violations, no class action has been filed specifically regarding the 2026 email breach.
  • North Texas Behavioral Health Authority breach: Several law firms have launched investigations in response to the breach and are considering filing a class-action lawsuit. Markovits, Stock & DeMarco stated that it was investigating claims on behalf of people affected by the NTBHA breach, while Schubert Jonckheer & Kolbe LLP announced an investigation into unauthorized access to information about about 285,000 individuals.

Can My Healthcare Information Be Used for Identity Theft?

Yes. Since these data breaches involve personally identifiable and protected health information, such as Social Security numbers, dates of birth, addresses, medical record numbers, and health insurance information, healthcare data can be used for identity theft.

Attackers may use a victim's insurance policy numbers and Social Security numbers to receive treatments, obtain prescription medications, or file fraudulent claims. This can lead to inaccurate entries appearing in your medical records. Additionally, cybercriminals may combine Social Security numbers with dates of birth and addresses to file false tax returns or open lines of credit.

What Can You Do to Protect Yourself Online?

Considering the sensitive nature of the data exposed across these incidents, it is important to take the following specific steps to protect yourself:

  • Consider a credit freeze or fraud alert: Contact all three major credit bureaus (Equifax, Experian, and TransUnion) to place a credit freeze, which prevents new accounts from being opened in your name. In addition, a fraud alert instructs creditors to verify your identity before opening a new credit account.
  • Enroll in credit and identity monitoring: The NTBHA has offered complimentary credit monitoring and identity theft protection services to individuals whose Social Security numbers were involved. You should check your notification letter for enrollment details. Individuals affected by the other two breaches should also check their notification letters for similar offers.
  • Review your Explanation of Benefits (EOB) statements: Go through all health insurance statements for treatments, prescriptions, or procedures you did not receive. Report any discrepancies to your insurer immediately.
  • Enable two-factor authentication (2FA): Activate 2FA on all important accounts, especially email, banking, and any patient portal accounts connected to the affected organizations.
  • Be alert for phishing: Do not click on links or download attachments in unsolicited emails or text messages, even if they appear to come from your healthcare provider. Always verify the sender's identity independently before engaging.
  • Change your patient portal passwords: Update login credentials for any online healthcare portals associated with Southern Illinois Dermatology, Saint Anthony Hospital, or North Texas Behavioral Health Authority. Avoid reusing the same password across multiple accounts.
  • Report suspected misuse immediately: If you believe your information is being misused, report it to the Federal Trade Commission at IdentityTheft.gov, and if you are in Texas, notify the Texas Attorney General's office. Illinois residents can file a complaint with the Illinois Attorney General.

 

Related Articles

What is Data Leak and How to Prevent Accidental Data Leakage

Data breaches take many forms, and one of them is through data leak and accidental web exposure. M ... Read More

The Saga of T-Mobile Data Breach: 2013, 2015, 2021 and 2023 Hacks

T-Mobile has experienced a number of data breaches in the past decade. The first case occurred som ... Read More

Anthem Data Breach Exposed 78 Million Records

In the Anthem Data Breach of 2015, hackers were able to steal 78.8 million member’s records. ... Read More

Everything You Need to Know About Insider Data Breach

Data breaches are on the news frequently, but the average person doesn’t really know that much a ... Read More

The NSA Hack, How Did it Happen?

The National Security Agency (NSA) was the main attraction in a major data breach involving three ... Read More

Latest Articles

What You Need to Know about the Amtrak Data Breach

What You Need to Know about the Amtrak Data Breach

Amtrak was created by Congress in 1970 as the National Railroad Passenger Corporation. It operates a nationwide rail network with over 300 trains serving more than 500 destinations in 46 states, three Canadian provinces, and the District of Columbia on more than 21,400 miles of route.

What You Need to Know about the Illinois and Texas Healthcare Data Breaches

What You Need to Know about the Illinois and Texas Healthcare Data Breaches

Three prominent healthcare organizations in the United States have officially disclosed major data breaches that have compromised the personal and medical information of about 600,000 people.

What You Need to Know about the Navia Benefit Solutions Data Breach

What You Need to Know about the Navia Benefit Solutions Data Breach

Navia Benefit Solutions, Inc. is a consumer-focused benefits administrator headquartered in Renton, Washington. Founded in 1989, the company provides comprehensive employee benefits administration services to more than 10,000 employers across the United States.

What You Need to Know about the QualDerm Partners Data Breach

What You Need to Know about the QualDerm Partners Data Breach

QualDerm Partners, LLC is a healthcare management services provider headquartered in Brentwood, Tennessee. The company offers comprehensive administrative, clinical, and operational support to dermatology practices nationwide.

What You Need to Know about the Healthcare Interactive Data Breach

What You Need to Know about the Healthcare Interactive Data Breach

Healthcare Interactive, Inc. , also known as HCIactive, is an Ellicott City, Maryland-based provider of AI-powered software solutions for insurance enrollment and benefits administration.

What You Need to Know about the Stryker Cyberattack

What You Need to Know about the Stryker Cyberattack

Stryker Corporation is a Fortune 500 medical technology company headquartered in Kalamazoo, Michigan. Founded in 1941, Stryker manufactures surgical equipment, orthopedic implants, neurotechnology, hospital beds, and robotic surgery systems.

Featured Articles

How to Buy a House with Bad Credit

How to Buy a House with Bad Credit

Buying your own home is the American Dream, but it might seem out of reach to those with bad credit. However, the good news is, if your credit is less than perfect, you do still have options and in most cases, can still buy a home.

How Secure Is Your Password? Tips to Improve Your Password Security

How Secure Is Your Password? Tips to Improve Your Password Security

Any good IT article on computers and network security will address the importance of strong, secure passwords. However, the challenge of good passwords is that most people have a hard time remembering them, so they use simple or obvious ones that pose a security risk.

Top 10 Senior Scams and How to Prevent Them

Top 10 Senior Scams and How to Prevent Them

Senior scams are becoming a major epidemic for two reasons. First, seniors often have a lot of money in the bank from a life of working hard and saving.

Notice

By proceeding with this scan, you agree to let IDStrong run a Free Scan of supplied parameters of your personal information and provide free preliminary findings in compliance with our Terms of Use and Privacy Notice. You consent to us using your provided information to complete the Free Scan and compare it against our records and breach databases or sources to provide your Free preliminary findings report.

Rest assured: IDStrong will not share your information with third parties or store your information beyond what is required to perform your scan and share your results.

Free Identity Threat Scan
Instantly Check if Your Personal Information is Exposed
All fields below are required
Please enter first name
Please enter last name
Please enter a city
Please select a state
Please enter an age
Please enter an email address
Close