Heart Care Centers of Illinois Data Breach Investigation

Heart Care Centers of Illinois recently disclosed a data security incident that, according to its notice, may have involved sensitive information belonging to employees and patients. The company said it identified historical suspicious activity tied to an employee email account and later determined that certain personal and protected health information may have been accessible. If you received a notice, it is important to review the details, use any free protection services offered, and watch for signs of misuse. You can also fill out the form on this page to contact Strauss Borrelli PLLC and learn whether you may have legal options.

Heart Care Centers of Illinois is a healthcare provider based in Palos Park, Illinois, focused on cardiovascular care. In July 2026, the organization posted a notice stating that a data security incident may have affected certain employees and patients.

Key Facts at a Glance

  • Company: Heart Care Centers of Illinois (HCCI)
  • Industry: Healthcare
  • Reported incident type: Hacking/IT incident involving an employee email account
  • Activity window: According to the company notice, unauthorized access occurred from August 22, 2024, to November 6, 2024
  • Discovery date: HCCI said it discovered suspicious activity on January 15, 2026
  • Notice timeline: Mailed notices reportedly began on July 10, 2026, and a public website notice was posted on July 18, 2026
  • Who may be affected: Employees and patients; the notice did not state an exact number
  • Information that may have been involved: Name, mailing address, Social Security number, date of birth, driver’s license or state ID number, payment card information, financial account information, passport number, medical information, prescription information, health insurance information, provider information, and telephone or fax number
  • Protection offered: Complimentary credit monitoring and identity restoration services through Epiq, with an enrollment deadline of October 31, 2026

What Happened?

According to Heart Care Centers of Illinois’ notice, the company discovered historical suspicious activity in an employee email account on January 15, 2026, while investigating an unsuccessful phishing attempt. HCCI said it then worked with third-party forensics specialists, who found evidence of a successful earlier phishing attack that led to unauthorized access during part of 2024.

The notice further states that a third-party data analytics firm reviewed the email account to determine what information may have been accessible and which people were potentially involved. HCCI reported that this review was completed on June 11, 2026, after which it began notifying potentially affected individuals and regulators. The company also stated that it had no reason to believe identity theft, fraud, or misuse had occurred in connection with the incident at the time of its notice.

What Information Was Exposed?

Heart Care Centers of Illinois said the information potentially involved varied from person to person. According to the notice, the data may have included both personal information and protected health information.

Examples listed by HCCI include names, addresses, Social Security numbers, dates of birth, driver’s license or state identification numbers, payment card information, financial account information, passport numbers, medical information such as treatment, condition, diagnosis, and prescription details, health insurance information, provider information, and telephone or fax numbers.

If you received a letter, the specific categories identified in that notice matter. Financial account details and Social Security numbers can increase identity theft risk, while medical and insurance information can create separate privacy and fraud concerns.

What Should You Do Next?

  1. Read your notice carefully. Confirm whether Heart Care Centers of Illinois identified specific categories of information that may have been involved in your case.
  2. Enroll in the free protection services. HCCI said it is offering complimentary credit monitoring and identity restoration through Epiq. If you received a code or enrollment instructions, consider using them before the stated October 31, 2026 deadline.
  3. Monitor your financial accounts and credit reports. Review bank, card, and insurance statements for unfamiliar activity. You may also consider placing a fraud alert or credit freeze if sensitive identifiers were involved.
  4. Watch for medical or insurance irregularities. Review explanation-of-benefits statements, provider bills, and account notices for services or claims you do not recognize.
  5. Keep records. Save the company notice, enrollment confirmations, screenshots, letters, and notes about any suspicious activity, time spent, or out-of-pocket losses.
  6. Ask questions and explore your rights. The notice lists 888-642-4224 for more information. If you want to understand whether this incident may support a legal claim, you can also contact Strauss Borrelli PLLC using the form provided on this page.

Your Legal Rights

If your personal or health information was potentially exposed, you may have legal rights depending on the facts and the laws that apply. In data incident matters, people sometimes seek relief for out-of-pocket losses, time spent responding to the incident, the cost of protective measures, and privacy-related harms.

Healthcare-related incidents can raise added concerns because medical and insurance information may be difficult to replace and may be misused in ways that are not immediately obvious. Whether a legal claim exists can depend on issues such as what information was involved, how the incident occurred, when notice was provided, and whether any misuse later appears.

A lawyer can help you understand what the notice means, what documents to preserve, and what deadlines may apply. This page is general information only and not individualized legal advice.

Why Hire Strauss Borrelli PLLC?

Strauss Borrelli PLLC represents individuals in data breach and privacy matters and understands how to evaluate incident notices, delayed discovery timelines, and the risks created by exposure of financial and health information. Our team works to explain these cases in plain English and focus on practical next steps for affected people.

If you received a notice from Heart Care Centers of Illinois or believe your information may have been involved, Strauss Borrelli PLLC can review the available facts, discuss whether you may qualify to pursue a claim, and help you understand the process. To get started, fill out the form on this page for a free, no-obligation review.

If you received a breach notification letter from Heart Care Centers of Illinois:

We would like to speak with you about your rights and potential legal remedies in response to this data breach. Please fill out the form, below, or contact us at 872.263.1100 or sam@straussborrelli.com.

Data Breach Website Blog Form

Contact Us

Learn about your legal rights

Name
Terms & Conditions and Privacy Policy

What can you do if you were impacted by a data breach?

If you were impacted by a data breach, you may consider taking the following steps to protect your personal information.

  1. Carefully review the breach notice and retain a copy;
  2. Enroll in any free credit monitoring services provided by the company;
  3. Change passwords and security questions for online accounts;
  4. Regularly review account statements for signs of fraud or unauthorized activity;
  5. Monitor credit reports for signs of identity theft; and
  6. Contact a credit bureau(s) to request a temporary fraud alert.

Contact Us Now

Data Breach Website Blog Form

What can you do if you were impacted by a data breach?

If you were impacted by a data breach, you may consider taking the following steps to protect your personal information.

  1. Carefully review the breach notice and retain a copy;
  2. Enroll in any free credit monitoring services provided by the company;
  3. Change passwords and security questions for online accounts;
  4. Regularly review account statements for signs of fraud or unauthorized activity;
  5. Monitor credit reports for signs of identity theft; and
  6. Contact a credit bureau(s) to request a temporary fraud alert.

One Magnificent Mile
980 N Michigan Avenue, Suite 1610
Chicago, Illinois 60611

Phone: 872.263.1100
Toll Free: 866.748.6220

One Magnificent Mile
980 N Michigan Avenue, Suite 1610
Chicago, Illinois 60611

Phone: 872.263.1100
Toll Free: 866.748.6220

©2026 STRAUSS BORRELLI PLLC. ALL RIGHTS RESERVED. ATTORNEY ADVERTISING.
PRIVACY POLICY  |  TERMS & CONDITIONS  |  COOKIE POLICY

©2026 STRAUSS BORRELLI PLLC. ALL RIGHTS RESERVED. ATTORNEY ADVERTISING.

PRIVACY POLICY  |  TERMS & CONDITIONS  |  COOKIE POLICY