The covered entity (CE), Illinois Gastroenterology Group, reported that several employees were the subjects of an email phishing scheme that compromised the protected health information (PHI) of 1,481 individuals. The PHI involved included names, addresses, dates of birth, Social Security numbers, diagnoses, lab results, medications, and other treatment information. The CE notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the CE provided complimentary credit monitoring services and implemented additional administrative, technical, and security safeguards. Staff were retrained.
2026-09-25 · attack: unknown to hacking · backfill source
2026-09-25 · data_types: [] to ["names","health"] · backfill source
2026-09-25 · summary: empty to The covered entity (CE), Illinois Gastroenterology Group, reported that several employees were the subjects of an email phishing scheme that compromised the protected health information (PHI) of 1,481 individuals. The PHI involved included · backfill source