A cardiology practice in Palos Park, Illinois, has disclosed a data breach in which an unauthorized party accessed an employee's email account for more than two months. The compromise went undetected for over a year and exposed health, financial, and identity data with direct implications for cyber and health insurance markets.
Heart Care Centers of Illinois (HCCI) said a phishing attack gave an unauthorized actor access to the employee's email account from August 22, 2024, to November 6, 2024. The practice did not discover the incident until January 15, while separately investigating a different, unsuccessful phishing attempt. The compromise was active for roughly 76 days but remained undetected for approximately 15 months.
The data potentially accessible in the account covers a broad range of sensitive categories. Names, mailing addresses, Social Security numbers, dates of birth, driver's license and state ID numbers, payment card information, financial account numbers, and passport numbers were among the types of data involved. Medical treatment and diagnosis information, prescription records, health insurance information, and provider details were also potentially accessible.
That combination of identity credentials, financial account data, and protected health information in a single incident is the profile cyber underwriters treat as high-severity. Social Security numbers and payment card data enable conventional fraud, while health insurance details enable medical identity theft, in which a bad actor uses a victim's coverage to obtain treatment or prescriptions under a false identity. Incorrect entries can end up in victims' own medical files and affect future diagnoses and insurance claims for years.
The timeline carries particular weight for cyber insurers. Insurers and risk managers who assess healthcare clients for phishing controls and detection capabilities will find the 15-month dwell time a material data point when evaluating incident response maturity.
The pattern is consistent with sector-wide trends. Coalition's 2026 Cyber Claims Report found business email compromise and funds transfer fraud together accounted for 58% of cyber incidents in 2025, while social engineering drove 57% of incurred cyber claims in the first half of 2025, according to Resilience data. Phishing-based, employee-targeted intrusions represent the dominant cause of cyber losses in the sector, not an edge case.
HCCI engaged third-party forensic specialists to investigate after discovery. It then hired a separate data analytics firm to review the compromised email account and identify whose information it contained. That secondary review concluded June 11, five months after discovery, and extended the period before affected individuals could be notified.
HCCI said it notified regulators as required by law and began sending written notices to potentially affected individuals on July 10. Under the Health Insurance Portability and Accountability Act (HIPAA), covered entities must notify affected individuals within 60 days of discovering a breach and report large-scale breaches to the US Department of Health and Human Services.
The notification timeline and any resulting regulatory scrutiny are standard coverage triggers under most healthcare cyber policies. HCCI said it did not have reason to believe the exposed data had been misused, and it is reviewing its existing policies and security measures in response to the incident. The practice is offering complimentary credit monitoring and identity restoration services through Epiq, with an enrollment deadline of October 31.