Illinois lawmaker questions IDHS over years-long data breach

Spread the love

(The Center Square) – An Illinois lawmaker slammed the state agency as “incompetent” after the Department of Human Services revealed it had accidentally exposed private health information of hundreds of thousands of residents on a public website and left it accessible for more than three years before discovering the breach.

State Sen. Terri Bryant, R-Murphysboro, said the breach, and the agency’s delayed public notification, follows a troubling pattern of data security failures across multiple state agencies under the Pritzker administration.

“This isn’t the first data breach,” Bryant told TCS. “What’s alarming is how long this information was publicly accessible and how long it took for people to be notified after the problem was discovered.”

IDHS said incorrect privacy settings exposed protected health information for more than 700,000 Illinois residents on an internal mapping website from 2021 until September 2025.

Although federal law requires public notification within 60 days, the agency waited 102 days to disclose the breach, a delay Bryant called legally and ethically troubling.

“IDHS is working to ensure that this does not happen again, as the privacy of customers is of paramount importance,” IDHS said in a recent news release.

“Federal law is clear. People are supposed to be notified within 60 days,” she said. “They discovered this in September, and here we are in January. To my knowledge, those notifications were not made on time, and the agency still won’t explain why.”

Bryant questioned whether contractors played a role in the breach, noting the exposed data overlaps with a period during the COVID-19 pandemic when the state awarded no-bid contracts to manage agency operations.

“There was a no-bid contract during COVID worth $21 to $22 million awarded to Deloitte to manage [the Illinois Department of Employment Security],” Bryant said. “I want to know whether this breach happened while contractors were involved or whether this was purely an internal failure. Either answer is bad, but the public deserves to know which it is.”

During COVID-19, Deloitte managed Illinois’ Pandemic Unemployment Assistance system, which experienced major data breaches that exposed personal information and led to lawsuits and settlements.

Bryant said repeated breaches across state agencies point to systemic failures rather than isolated mistakes.

“If this is really about something as simple as incorrect privacy settings, that’s even more concerning,” she said. “This is extremely sensitive information, financial data and medical information. There should be safeguards in place, and there should be someone clearly responsible for making sure those safeguards work.”

Bryant also highlighted the April 2021 ransomware attack on the Illinois Attorney General’s office, which exposed names, addresses, and Social Security numbers of potentially millions of residents after hackers using DoppelPaymer malware posted data when ransom demands failed, forcing the state to spend heavily on cybersecurity recovery and forensic audits.

She compared the current situation to an incident she witnessed decades ago while working for the Illinois Department of Corrections, when a far smaller exposure of sensitive information prompted immediate notification and serious disciplinary action.

“That situation was handled quickly, efficiently and transparently,” Bryant said. “That’s not what we’re seeing today.”

Bryant said affected individuals should, at a minimum, receive free credit monitoring, adding that similar measures were taken following previous breaches at state agencies.

“The taxpayers are probably going to end up footing the bill again,” she said. “That’s unacceptable when these breaches are preventable.”

IDHS said it has since implemented a new Secure Map Policy that prohibits uploading any customer-level data to public mapping websites and restricts access to authorized personnel.

Bryant said Republican senators plan to raise the issue during leadership meetings and push for answers, though she acknowledged that Democrats control the General Assembly.

“We’re in a super minority, so we don’t get to set hearings,” she said. “But we will be asking why people weren’t notified, what’s being done now, and how the state plans to make sure this never happens again.”

TCS asked IDHS why it took over three years to discover the breach, why notification took more than 100 days, whether a contractor was responsible, if the agency will compensate affected residents, and how it plans to respond to Republican senators pushing for answers. IDHS did not immediately respond.

Leave a Comment





Latest News Stories

State rep calls out violent rhetoric after Pritzker commission rips federal officers

State rep calls out violent rhetoric after Pritzker commission rips federal officers

By Jim Talamonti | The Center SquareThe Center Square (The Center Square) – After the first meeting of the Illinois Accountability Commission, a Republican state representative says Gov. J.B. Pritzker’s...
Report: Phoenix, Salt Lake City top airports for holiday travel

Report: Phoenix, Salt Lake City top airports for holiday travel

By Zachery SchmidtThe Center Square Phoenix Sky Harbor International Airport and Salt Lake City International Airport rank as the nation's top two airports for smooth travel during the holiday season,...
$3.5M verdict tossed; Judge shielded evidence of plaintiff’s dishonesty, crime

$3.5M verdict tossed; Judge shielded evidence of plaintiff’s dishonesty, crime

By Scott Holland | Legal NewslineThe Center Square A state appeals panel voided a $3.5 million verdict awarded to a man who claimed he was hurt while working for Union...
HHS takes sweeping action to reverse Biden-era policies on gender affirming care

HHS takes sweeping action to reverse Biden-era policies on gender affirming care

By Morgan SweeneyThe Center Square The U.S. Department of Health and Human Services unveiled a multi-pronged regulatory effort Thursday to curtail gender-affirming care for minors, including gender transition procedures at...
Trump signs order reclassifying marijuana as Schedule III drug

Trump signs order reclassifying marijuana as Schedule III drug

By Thérèse BoudreauxThe Center Square President Donald Trump signed an executive order to reclassify marijuana from a Schedule I to a Schedule III controlled substance, despite many Republican lawmakers urging...
Poll: Americans back criminal and homelessness reform

Poll: Americans back criminal and homelessness reform

By Zachery SchmidtThe Center Square This story has been updated since its initial publication. Americans support stricter criminal measures and homelessness reform, according to a new poll by The Cicero...
U.S. troops to get $1,776 tax-free bonuses by Dec. 20

U.S. troops to get $1,776 tax-free bonuses by Dec. 20

By Andrew RiceThe Center Square U.S. troops will get a bonus before Christmas this year that will cost taxpayers about $2.6 billion. President Donald Trump announced a $1,776 tax-free "Warrior...
New action taken to strengthen US military chaplain corps

New action taken to strengthen US military chaplain corps

By Bethany BlankleyThe Center Square Secretary of War Pete Hegseth issued a new directive to revamp the U.S. military Chaplain Corps. The new directive was issued one week after a...
Federal judge blocks ICE policy on lawmaker visits

Federal judge blocks ICE policy on lawmaker visits

By Chris WadeThe Center Square Members of Congress will be allowed to visit ICE facilities without notice and may inspect migrant detention areas under a new ruling by a federal...
Illinois quick hits: Increased energy prices expected; IHSA changes approved

Illinois quick hits: Increased energy prices expected; IHSA changes approved

By The Center SquareThe Center Square Increased energy prices expected The Citizens Utility Board says ComEd customers can expect continued high prices after grid operator PJM Interconnection released the results...
Pritzker disputes Trump claims, says Illinois GOP backs president '100%'

Pritzker disputes Trump claims, says Illinois GOP backs president ‘100%’

By Jim Talamonti | The Center SquareThe Center Square (The Center Square) – Gov. J.B. Pritzker says Illinois Republicans are letting President Donald Trump get away with boasting about higher...
WATCH: Pritzker reacts to Trump’s address; Immigration enforcement continues

WATCH: Pritzker reacts to Trump’s address; Immigration enforcement continues

By Greg Bishop | The Center SquareThe Center Square (The Center Square) – In today's edition of Illinois in Focus Daily, The Center Square Editor Greg Bishop shares highlights from...
D.C.’s power to challenge Trump in jeopardy after Guard ruling

D.C.’s power to challenge Trump in jeopardy after Guard ruling

By Daniel Fisher | Legal NewslineThe Center Square A federal court’s slapdown of the District of Columbia’s lawsuit against the Trump administration over the deployment of National Guard troops could...
November inflation at 2.7%, lower than expected

November inflation at 2.7%, lower than expected

By Andrew RiceThe Center Square Consumer prices rose by 0.2% in the two month period between September and November. In the past 12 months, overall prices rose by 2.7%, which...
Sophomore Landon Justice rises up to score over a Neoga defender. Justice dominated the JV contest with 20 points and 13 rebounds. —photo by Terri Cox

Warriors overcome slow start to handle Neoga, remain undefeated

Featured Photo Caption: Sophomore Landon Justice rises up to score over a Neoga defender. Justice dominated the JV contest with 20 points and 13 rebounds. —photo by Terri Cox By...