Skip to content

University of Chicago Medical Center

Disclosed May 24, 20242 years ago10,332 affectedConfirmed

Official notice

The covered entity (CE), University of Chicago Medical Center, reported that multiple employees were the subjects of an email phishing attack that affected the protected health information (PHI) of 10,332 individuals. The PHI involved included names, dates of birth, Social Security numbers, passport numbers, drivers’ license or state identification numbers, financial information, diagnoses, medications, and health insurance and other treatment information. The CE notified HHS, the affected individuals, the media, and provided substitute notice. In response to the breach, the CE provided complimentary credit monitoring services and implemented additional administrative, technical, and security safeguards. Staff were retrained on email security.

What is known

People affected10,332 (as reported by the organization)
DisclosedMay 24, 2024
HappenedJan 4, 2024
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
Indiana AGresidents of INMay 24, 20241,463
HHS archivetotalMay 24, 202410,332

Other breaches at University of Chicago Medical Center

BreachAffected
Disclosed May 27, 2022May 27, 20224 years agoHacking2,568
History of this record
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · summary: empty to The covered entity (CE), University of Chicago Medical Center, reported that multiple employees were the subjects of an email phishing attack that affected the protected health information (PHI) of 10,332 individuals. The PHI involved inclu · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.

Everything about University of Chicago Medical Center

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.