CSIDB logo
Incident

Erie Family Health Centers

Incident posture

Attack window
Dec 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-01 10:03

Linked entities

Victim
Erie Family Health Centers
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Dec 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Erie Family Health Centers in Chicago detected a hacker attack in January 2026, with threat actors accessing its network from December 10, 2025 to late January 2026, compromising names, phone numbers, emails, SSNs, driver’s license, passport numbers, online credentials, financial, and medical data of 570,000 individuals.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

Erie Family Health Centers, a healthcare provider based in Chicago, Illinois, experienced a data breach that was detected in January 2026, following an investigation that determined unauthorized actors had maintained access to its network over a period of approximately two months. The window of unauthorized access began on December 10, 2025, and continued until late January 2026. During that timeframe, the attackers were able to infiltrate the organization's systems and remain undetected for the majority of the access period. Once the intrusion was identified in January, Erie Family Health Centers initiated an investigation to determine the scope of the compromise, the nature of the information exposed, and the timeline of attacker activity. The findings of that investigation were subsequently reported to the U.S. Department of Health and Human Services, where the incident was added to the federal healthcare data breach tracker.

The scope of the breach at Erie Family Health Centers was substantial, affecting approximately 570,000 individuals according to the HHS breach tracker. The information exposed in the incident was broad and included a wide range of personally identifiable and sensitive categories. Compromised data included names, telephone numbers, email addresses, Social Security numbers, driver's license numbers, passport numbers, online account credentials, financial information, and medical information. The combination of identifiers, financial data, and medical details made the exposed information particularly sensitive for those affected. The disclosure of this combination of data types increased the potential for identity theft, financial fraud, and other forms of misuse against the impacted individuals, given that medical and financial information are commonly targeted for exploitation following healthcare data breaches.

Erie Family Health Centers operates as a community health provider serving patients in the Chicago area, and the breach had implications for a significant portion of its patient population and associated individuals whose data was stored within the compromised network. The organization was among several major U.S. healthcare entities that reported data breaches to the HHS tracker in the same general period, alongside the New York City Health and Hospitals Corporation, Florida Physician Specialists, Coastal Carolina Health Care, Western Orthopaedics, and Nacogdoches Memorial Hospital. Erie's incident stood out due to both the number of individuals affected and the breadth of data categories involved, as the combination of SSNs, financial information, and medical records represented one of the more comprehensive sets of exposed data among the breaches reported during that timeframe. No cybercrime group publicly claimed responsibility for the attack, consistent with the broader pattern observed in the other major healthcare breaches disclosed around the same period.

Following the detection of the intrusion, Erie Family Health Centers moved through the standard post-incident process of investigating the breach, determining the affected data, and reporting the incident to the appropriate federal regulators. The organization disclosed the breach publicly through its listing on the HHS breach tracker, making the number of affected individuals and the categories of exposed data available to the public. The affected individuals were drawn from those whose information was stored in the compromised network segments, and the wide variety of data types exposed indicated that the attackers were able to reach systems containing a broad cross-section of personal, financial, and medical records. The breach was reported alongside several other major healthcare incidents in early-to-mid 2026, each involving different attack vectors and durations of unauthorized access, with Erie's incident distinguished by its multi-month attacker dwell time and the diversity of compromised data elements.

Sources

Sources available to members: 1 source.

CSIDB