City of Chicago
Disclosed Nov 29, 201312 years ago2,080 affectedConfirmed
The covered entity (CE) mistakenly permitted protected health information (PHI) to be viewable on the Internet when users uploaded files without changing the default permission settings for the folders containing the files. As a result, Google was able to detect and cache the PHI in the uploaded folders. Approximately 2,080 individuals were affected by this breach. The types of PHI involved in the breach included students’ names, birthdates, genders, identification numbers, vision exam dates, diagnoses, and schools. The CE provided breach notification to HHS, the parents and guardians of affected individuals, and the media. It also posted notice on its website. The CE took action to remove the files containing PHI from its network and compiled a list of files along with the associated unique record locator numbers (URLs) and cached URLs. The CE contacted Google to request removal of the data from the cache and the archives, and Google confirmed that the data was removed. OCR obtained assurances that the CE implemented the corrective actions listed above.
What is known
| People affected | 2,080 (as reported to HHS) |
|---|---|
| Disclosed | Nov 29, 2013 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): City of Chicago (Healthcare Provider, IL)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Nov 29, 2013 | 2,080 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.