
The Illinois Department of Human Services (IDHS) recently disclosed a major data exposure incident involving misconfigured internal planning maps that were publicly accessible for years.This breach impacted approximately 700,000 residents, primarily Medicaid/Medicare recipients and rehabilitation services clients.
Breach Overview
IDHS’s Division of Family and Community Services created resource allocation maps on a third-party mapping platform, but incorrect privacy settings left them exposed online. The issue was discovered on September 22, 2025, with full access restrictions implemented by September 26, 2025, after a comprehensive data review.
Exposure Duration by Dataset
Medicaid/Medicare Savings Program – 672,616 – January 2022 September 2025 – ~3 years 9 months
Division of Rehabilitation Services – 32,401- April 2021- September 2025- ~4 years 5 months
These timelines confirm the maps were unintentionally public for extended periods before detection.
Exposed Data Types
- Medicaid/Medicare maps: Addresses, case numbers, demographics, and medical assistance plan names (names excluded).
- Rehabilitation maps: Names, addresses, case details, and referral information.
No evidence of data misuse has surfaced to date.
IDHS Response and Mitigation
IDHS enacted a Secure Map Policy prohibiting customer data on public mapping sites and role-based access controls. Notifications went out to affected individuals, with reports filed to regulators including the HHS Office for Civil Rights.This follows a separate December 2024 phishing incident impacting 1.1 million customers.



