S&P 5007,533.77▼0.5% Nasdaq25,881.95▼1.5% Dow52,552.97▼0.2% Russell 2K2,974.57▼0.1% 10-Yr4.57%+2bp VIX16.73+1.06 WTI$79.00▼0.8% Gold$3,981.40▼1.6% EUR/USD1.145▼0.2% BTC$65,448▲1.2% Nikkei68,752▲1.5%
At close · Thu, Jul 16, 2026
Daily Market Updates.

Insurance

HomeInsuranceHealth InsurancePhishing attack at Illinois cardiology practice expose…

Phishing attack at Illinois cardiology practice exposed sensitive data

The incident stayed active for about 76 days but was not discovered until January 15, 2025, after a 15-month dwell time.

Heart Care Centers of Illinois disclosed a data breach after an unauthorized actor accessed an employee email account via phishing, with the compromise running from Aug. 22, 2024 to Nov. 6, 2024. The practice did not discover the incident until Jan. 15, after investigating a separate, unsuccessful phishing attempt, leaving the breach undetected for roughly 15 months.

According to Insurance Business, the email account potentially exposed a wide range of sensitive data, including names, mailing addresses, Social Security numbers, dates of birth, and government ID numbers, as well as payment card information, financial account numbers, and passport numbers.

The potential data also included health-related records, such as medical treatment and diagnosis information, prescription records, health insurance information, and provider details. The outlet notes that combining identity credentials, financial data, and protected health information creates a high-severity profile for cyber insurers.

Insurance Business said the timeline matters for cyber underwriters assessing healthcare clients, citing sector patterns where business email compromise and social engineering are major drivers of cyber incidents and incurred claims. The practice engaged third-party forensic specialists to investigate the intrusion.

More like this

Sources

Get the close, explained.

One email every trading day: what moved, why it moved, and what's on deck tomorrow. Read in 3 minutes.

Free. Unsubscribe anytime.