Two Unique DHS Cyber Incidents Exposed 1M People's Data
Briefly

Two Unique DHS Cyber Incidents Exposed 1M People's Data
"Maps created by the department's Division of Family and Community Services' Bureau of Planning and Evaluation were found to be publicly viewable in result of incorrect privacy settings. These were intended for internal use only. According to the IDHS, the data leak may impact the two following categories: Division of Rehabilitation Services (DRS) Customers: The data of approximately 32,401 individuals were impacted, involving information such as "names, addresses, case numbers, case status, referral source information, region and office information, and status as DRS recipients.""
"Medicaid and Medicare Savings Program Recipients: 672,616 individuals were estimated to be impacted, including "addresses, case numbers, demographic information, and the name of medical assistance plans (such as Medicaid, Medicare, etc.)." However, names were not exposed. In total, the IDHS data leak approximates 700,000 residents affected. At this time, IDHS is unable to identify who viewed the maps. Likewise, it is unknown if any personal information has been misused as a result of this exposure."
Illinois DHS discovered on Sep. 22, 2025 that internally intended maps were publicly viewable due to incorrect privacy settings. The exposure affected about 32,401 Division of Rehabilitation Services customers and about 672,616 Medicaid and Medicare Savings Program recipients, totaling roughly 700,000 residents; names were not exposed for the Medicaid group. The department cannot determine who viewed the maps or whether data were misused. Separately, FEI Systems discovered a Nov. 18, 2025 security event involving MnCHOICES and reported it on Nov. 19; the department announced unauthorized access by a licensed health care provider-affiliated user on Jan. 16, 2026.
Read at Securitymagazine
Unable to calculate read time
[
|
]