Southern Illinois Hospital Services
Disclosed Jun 23, 20179 years ago613 affectedConfirmed
The covered entity (CE), Southern Illinois Hospital Services, reported that its business associate misdirected the electronic protected health information (ePHI) of 613 individuals to the wrong medical facilities. The ePHI involved included names, dates of birth, gender, addresses, and health insurance information. The CE notified HHS, affected individuals, the media, and provided substitute notice. Complimentary identity protection services were provided to affected individuals. In its mitigation efforts, the BA implemented additional administrative, technical, and security safeguards to better protect ePHI.
What is known
| People affected | 613 (as reported by the organization) |
|---|---|
| Disclosed | Jun 23, 2017 |
| Happened | Feb 13, 2017 |
| Attack | Insider |
| Data exposed | Names, Payment cards, Financial, Passwords, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Indiana Attorney General 2017 data breach report: Southern Illinois Hospital Servicesin.gov · Official notice | Official notice |
| Maine Attorney General breach notice archive: Southern Illinois Hospital Servicesmaine.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Southern Illinois Hospital Services (Healthcare Provider, IL)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Indiana AGresidents of IN | Jun 23, 2017 | 1 |
| Maine AGresidents of ME | Jun 23, 2017 | 1 |
| HHS archivetotal | Jun 23, 2017 | 613 |
History of this record
- 2026-09-25 · attack: unknown to insider · backfill source
- 2026-09-25 · data_types: ["names","payment-card","financial","passwords"] to ["names","payment-card","financial","passwords","health"] · backfill source
- 2026-09-25 · summary: empty to The covered entity (CE), Southern Illinois Hospital Services, reported that its business associate misdirected the electronic protected health information (ePHI) of 613 individuals to the wrong medical facilities. The ePHI involved included · backfill source
- 2026-09-25 · data_types: [] to ["names","payment-card","financial","passwords"] · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.