Skip to content

Advocate Medical Group

Disclosed Aug 23, 201313 years ago4,029,530 affectedSettled

Official notice

Four stolen desktop computers held data on 4 million Advocate patients

Unencrypted desktop computers were stolen from an Advocate Medical Group administrative office in Illinois, exposing data of about 4 million patients. Advocate later paid a record $5.55 million HIPAA settlement covering this and other breaches.

What is known

People affected4,029,530 (as reported by the organization)
DisclosedAug 23, 2013
HappenedJul 15, 2013
AttackLost or stolen device
Data exposedNames, Addresses, Dates of birth, Social Security numbers, Health, Insurance
SectorHealthcare · US
StatusSettled
Lawsuit or fine$5.55M HHS OCR HIPAA settlement (2016) (about $5.5M)

Sources

Notices filed

WhereFiledPeople
California AGresidents of CAAug 23, 2013
ResearchtotalAug 23, 20134,029,530
History of this record
  • 2026-09-25 · status: confirmed to settled · seed source
  • 2026-09-25 · fine_usd: empty to 5550000 · seed source
  • 2026-09-25 · lawsuit: empty to $5.55M HHS OCR HIPAA settlement (2016) · seed source
  • 2026-09-25 · attack: unknown to lost-device · seed source
  • 2026-09-25 · data_types: [] to ["names","addresses","dob","ssn","health","insurance"] · seed source
  • 2026-09-25 · records_basis: empty to organization · seed source
  • 2026-09-25 · records: empty to 4029530 · seed source
  • 2026-09-25 · summary: empty to Unencrypted desktop computers were stolen from an Advocate Medical Group administrative office in Illinois, exposing data of about 4 million patients. Advocate later paid a record $5.55 million HIPAA settlement covering this and other breac · seed source
  • 2026-09-25 · title: empty to Four stolen desktop computers held data on 4 million Advocate patients · seed source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about Advocate Medical Group

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.