Saint Anthony Hospital in Chicago disclosed that unauthorized actors accessed and/or stole files and folders containing unstructured data from its email system on February 27, 2025, exposing sensitive information tied to 146,108 individuals. The hospital said its electronic medical records were not affected, but the compromised data included names, addresses, dates of birth, Social Security numbers, medical record numbers, patient account numbers, prescription information, and medical histories.
The incident was initially reported as affecting about 6,600 patients and employees, but a later filing with the HHS Office for Civil Rights sharply increased the total impact. Third-party specialists completed their review on February 13, 2026, and notification letters began mailing on March 6, 2026, more than a year after the intrusion. Saint Anthony said it found no evidence of actual or attempted misuse of the data, while urging affected individuals to monitor credit reports, financial accounts, and explanation of benefits statements; reports indicate complimentary credit monitoring and identity theft protection were not offered.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
By April 2026, a breach notice filed with the HHS Office for Civil Rights indicated the incident affected 146,108 individuals, sharply increasing the known scope from the hospital's earlier estimate. Reporting also noted that complimentary credit monitoring and identity theft protection did not appear to have been offered.
Saint Anthony Hospital began sending notification letters to affected individuals on March 6, 2026, more than a year after the unauthorized access. The hospital said it found no evidence of actual or attempted misuse and advised recipients to monitor credit, financial, and benefits statements.
Third-party specialists completed their review of the breach on February 13, 2026. The completed review led to a much larger confirmed impact than initially reported.
In November 2025, Saint Anthony Hospital initially disclosed the incident as affecting roughly 6,600 patients and employees. The exposed data was described as including names, addresses, dates of birth, Social Security numbers, medical record numbers, patient account numbers, prescription information, and medical histories.
On February 27, 2025, Saint Anthony Hospital said unauthorized actors accessed and/or stole files and folders of unstructured data from its email system. The hospital stated its electronic medical records were not affected.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.