Skip to content

Lutheran Social Services of Illinois

Disclosed Mar 25, 20224 years ago150,659 affectedConfirmed

Official notice

The covered entity (CE), Lutheran Social Services of Illinois, reported that it experienced a ransomware attack affecting the protected health information (PHI) of 146,028 individuals. The PHI involved included names, addresses, phone numbers, email addresses, dates of birth, Social Security numbers, diagnoses, lab results, prescription information, financial information, and health insurance and claim information. The CE notified HHS, the affected individuals, the media, and provided substitute notice. In response to the breach, the CE provided complimentary credit monitoring services, implemented additional administrative and technical safeguards to better protect its PHI, and received technical assistance from OCR regarding the HIPAA Rules.

What is known

People affected150,659 (as reported by the organization)
DisclosedMar 25, 2022
HappenedDec 31, 2021
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalMar 25, 2022146,028
Indiana AGresidents of INJan 25, 2023641
History of this record
  • 2026-09-25 · sector: other to health · backfill source
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · disclosed: 2023-01-25 to 2022-03-25 · backfill source
  • 2026-09-25 · summary: empty to The covered entity (CE), Lutheran Social Services of Illinois, reported that it experienced a ransomware attack affecting the protected health information (PHI) of 146,028 individuals. The PHI involved included names, addresses, phone numbe · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.

Everything about Lutheran Social Services of Illinois

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.