IDHS Data Breach: Years of Exposed Sensitive Maps Affecting 700K Residents

IDHS Data Breach: Years of Exposed Sensitive Maps Affecting 700K Residents


The Illinois Department of Human Services (IDHS) recently disclosed a major data exposure incident involving misconfigured internal planning maps that were publicly accessible for years.This breach impacted approximately 700,000 residents, primarily Medicaid/Medicare recipients and rehabilitation services clients.

Breach Overview

IDHS’s Division of Family and Community Services created resource allocation maps on a third-party mapping platform, but incorrect privacy settings left them exposed online. The issue was discovered on September 22, 2025, with full access restrictions implemented by September 26, 2025, after a comprehensive data review.

Exposure Duration by Dataset

Medicaid/Medicare Savings Program – 672,616 – January 2022 September 2025 – ~3 years 9 months

Division of Rehabilitation Services – 32,401- April 2021- September 2025-  ~4 years 5 months

These timelines confirm the maps were unintentionally public for extended periods before detection.

Exposed Data Types

  • Medicaid/Medicare maps: Addresses, case numbers, demographics, and medical assistance plan names (names excluded).
  • Rehabilitation maps: Names, addresses, case details, and referral information.

No evidence of data misuse has surfaced to date.

IDHS Response and Mitigation

IDHS enacted a Secure Map Policy prohibiting customer data on public mapping sites and role-based access controls. Notifications went out to affected individuals, with reports filed to regulators including the HHS Office for Civil Rights.This follows a separate December 2024 phishing incident impacting 1.1 million customers.

Comments

No comments yet. Why don’t you start the discussion?

    Leave a Reply

    This site uses Akismet to reduce spam. Learn how your comment data is processed.