Southern Illinois Ob-Gyn Associates experienced a data breach that was first detected on November 24, 2025. Unauthorized access was confirmed on January 28, 2026, and the final notification list was obtained on April 28, 2026. The company disclosed the incident to the U.S. Department of Health and Human Services on May 22, 2026.
Affected individuals include 38,700 current and former patients. The exposed data types include names, dates of birth, Social Security numbers, demographic information, health information, and health insurance numbers. While the company operates in Illinois, notification to the New Hampshire Attorney General suggests potential patient records in that state may also have been affected.
Details can continue to emerge, and official notices may be delayed.