Cancer Treatment Centers of America at Midwestern Regional Medical Center
Disclosed Mar 19, 20215 years ago104,808 affectedConfirmed
Cancer Treatment Centers of America at Midwestern Regional Medical Center, the covered entity (CE), reported that an employee was the subject of an email phishing scheme that compromised the protected health information (PHI) of 104,808 individuals. The PHI involved included names, medical record numbers, health insurance information, and treatment information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In its mitigation efforts, the CE implemented additional administrative, technical, and security safeguards to better protect its sensitive data. All staff were retrained.
What is known
| People affected | 104,808 (as reported to HHS) |
|---|---|
| Disclosed | Mar 19, 2021 |
| Discovered | Jan 18, 2021 |
| Happened | Jan 12, 2021 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| California Attorney General breach notice: Cancer Treatment Centers of America at Midwestern Regional Medical Centeroag.ca.gov · Official notice | Official notice |
| Oregon DOJ breach notice: Cancer Treatment Centers of America at Midwestern Regional Medical Centerjustice.oregon.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Cancer Treatment Centers of America at Midwestern Regional Medical Center (Healthcare Provider, IL)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| California AGresidents of CA | Mar 19, 2021 | |
| Oregon DOJresidents of OR | Mar 19, 2021 | 104,000 |
| HHS archivetotal | Mar 19, 2021 | 104,808 |
History of this record
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · records_basis: empty to hhs · backfill source
- 2026-09-25 · records: empty to 104808 · backfill source
- 2026-09-25 · summary: empty to Cancer Treatment Centers of America at Midwestern Regional Medical Center, the covered entity (CE), reported that an employee was the subject of an email phishing scheme that compromised the protected health information (PHI) of 104,808 ind · backfill source
- 2026-09-25 · discovered: empty to 2021-01-18 · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.
Everything about Cancer Treatment Centers of America at Midwestern Regional Medical Center