Were you recently affected by a data breach?

Lake County Health Department and Community Health Center Data Breach

Lake County Health Department and Community Health Center in Waukegan, Illinois notified 981 patients that a billing statement printing error caused some patients’ names and account numbers to be mailed to the wrong recipient. Affected individuals may be entitled to compensation through a data breach lawsuit.

Lake County Health Department and Community Health Center
Date of Breach: Billing statements dated May 16, 2026; discovered by LCHD/CHC on May 22, 2026
CAU logo

Who was affected:

Clients of Lake County Health Department and Community Health Center

Impacted Data:

First names and account numbers (no Social Security numbers or financial account information involved)

Lake County Health Department and Community Health Center (LCHD/CHC), a public health provider based in Waukegan, Illinois, has notified nearly 1,000 patients that a billing error resulted in some of their personal information being mailed to the wrong person. The health department disclosed the incident to federal regulators as an unauthorized access or disclosure involving paper records.

Healthcare providers are entrusted with sensitive patient information, including billing and account details, and have a responsibility to ensure that information reaches only the intended recipient. When a mailing or printing error causes that information to be misdirected, the organization responsible may be held accountable.

Lake County Health Department and Community Health Center’s Data Breach Investigation

According to a notification letter sent to affected patients and a filing with the U.S. Department of Health and Human Services’ Office for Civil Rights (HHS OCR), LCHD/CHC discovered on May 22, 2026 that some billing statements dated May 16, 2026 contained incorrect patient information due to a printing error. As a result, information associated with a patient’s account, or the account of a member of their household, may have been included on a billing statement sent to a different individual. The health department’s letter, signed by Privacy Officer Brenda Ruelas, states that the information involved may have included first names and account numbers, and specifically notes that no Social Security numbers or financial account information were included in the misdirected statements.

LCHD/CHC’s own letter states that upon discovering the error, the health department promptly investigated the incident, identified the affected individuals, and attempted to retrieve or securely destroy any misdirected billing statements where possible. The organization also says it has no evidence that any information has been misused and is notifying patients out of an abundance of caution, while recommending that recipients review any statements they receive and contact the health department if they notice unfamiliar or inaccurate information.

HHS OCR’s public breach portal lists this incident as affecting approximately 981 individuals, reported as an Unauthorized Access/Disclosure involving Paper/Films, with no business associate identified as being involved. Unlike a hacking or ransomware incident, this breach originated from an internal printing and mailing process error rather than an external cyberattack, but the notification and reporting obligations under HIPAA’s Breach Notification Rule apply the same way regardless of whether a breach results from a malicious intrusion or an internal administrative mistake.

Printing and mailing errors of this kind are a recurring category of healthcare data breach. Because billing systems often merge account and demographic data automatically before printing, a single software or process error can misdirect information for many patients in a single mailing run, as appears to have happened here. Even when the exposed information is limited, as LCHD/CHC states is the case in this incident, recipients whose names and account numbers were sent to a stranger may still face an increased risk of follow-up phishing attempts by people posing as the health department, an insurer, or a billing company in order to extract additional personal information.

When Did This Breach Occur?

The billing statements at the center of this incident were dated May 16, 2026. LCHD/CHC states it discovered the printing error on May 22, 2026, and the organization’s formal notification letter to affected patients is dated June 22, 2026. The federal HHS OCR filing reflects a breach submission date of July 17, 2026, which represents when the incident was formally reported to regulators rather than when the underlying error occurred or was discovered.

What Information Was Breached?

Per LCHD/CHC’s own notification letter, the information involved in this incident was limited to first names and account numbers. The health department’s letter explicitly states that no Social Security numbers or financial account information were included in the misdirected billing statements. This is a narrower scope of exposed information than many healthcare data breaches, which often involve more extensive medical or financial detail, though any unauthorized disclosure of a patient’s personal information tied to a healthcare account carries a privacy risk worth taking seriously.

What You Can Do

If you are a current or former patient or client of Lake County Health Department and Community Health Center, there are several steps you can take to help protect yourself:

  • Review the notification letter from LCHD/CHC carefully, and contact the Privacy Officer with any questions.
  • Check any billing statements or account correspondence you receive for information that appears inaccurate, unfamiliar, or belonging to someone else.
  • If you receive a statement containing another patient’s information, securely destroy it or return it to the health department rather than copying, using, or further disclosing it.
  • Monitor your account statements for any activity you do not recognize.
  • Be cautious of unsolicited calls, texts, or emails claiming to be from the health department, an insurer, or a billing company asking you to verify personal information.
  • Keep the notification letter and any related correspondence in case you need it later.

File a Data Breach Lawsuit Against Lake County Health Department and Community Health Center

If your personal information was compromised as a result of this data breach, you may be entitled to compensation for the harm it caused, including the time and expense of monitoring your accounts and the risk of identity theft or fraud going forward. Healthcare providers have a legal responsibility to implement reasonable safeguards, including in their billing and mailing processes, to protect the personal information entrusted to them, and a failure to do so can form the basis of a data breach lawsuit.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Billing statements dated May 16, 2026; discovered by LCHD/CHC on May 22, 2026
Date of Breach: Reported to HHS OCR on July 31, 2026 (exact incident date not publicly disclosed)
Date of Breach: Claimed August 18, 2026 (unconfirmed by the practice)
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.