Find notable cyber news and cases, enriched with sources, timelines, and signals.

Illinois Department of Human Services public mapping website data exposure

Data Leak
First reported
Last updated
Happening score
H score 22
1 unique sources, 1 articles

Summary

Hide ▲

Illinois Department of Human Services (IDHS) exposed personal and health data for nearly 700,000 Illinois residents after incorrect privacy settings left internal maps publicly viewable on a mapping website. The exposure affected 672,616 Medicaid and Medicare Savings Program recipients and 32,401 Division of Rehabilitation Services customers, with records including addresses, case numbers, demographic details, plan names, names, case status, and referral sources. IDHS discovered the problem on September 22, 2025 and finished locking down access by September 26. The agency is notifying affected people and regulators and says it is unaware of actual or attempted misuse.

Timeline

  1. 09.01.2026 17:37 1 articles · 4mo ago

    IDHS discovers publicly viewable mapping website data

    Initial Disclosure

    On September 22, 2025, IDHS discovered that maps created by the Division of Family and Community Services' Bureau of Planning and Evaluation were publicly viewable on a mapping website because of incorrect privacy settings.

    Show sources
  2. 09.01.2026 17:37 1 articles · 4mo ago

    IDHS locks down access to exposed maps

    Mitigation Patch Update

    On September 26, 2025, IDHS completed a lockdown that restricted access to the exposed maps to authorized employees and then reviewed the exposed maps while blocking attempts to upload identifiable customer information to public mapping platforms.

    Show sources
  3. 09.01.2026 17:37 2 articles · 4mo ago

    IDHS reports exposed resident data and lack of known misuse

    Victim Impact Update

    On January 9, 2026, IDHS reported that the public exposure affected 672,616 Medicaid and Medicare Savings Program recipients and 32,401 Division of Rehabilitation Services customers, exposing addresses, case numbers, demographic details, medical assistance plan names, names, case status, and referral sources; IDHS also said it was unaware of any actual or attempted misuse and was notifying affected individuals and regulators.

    Show sources