Lake County Health Department and Community Health Center (LCHD/CHC), a public health provider based in Waukegan, Illinois, has notified nearly 1,000 patients that a billing error resulted in some of their personal information being mailed to the wrong person. The health department disclosed the incident to federal regulators as an unauthorized access or disclosure involving paper records.
Healthcare providers are entrusted with sensitive patient information, including billing and account details, and have a responsibility to ensure that information reaches only the intended recipient. When a mailing or printing error causes that information to be misdirected, the organization responsible may be held accountable.
Lake County Health Department and Community Health Center’s Data Breach Investigation
According to a notification letter sent to affected patients and a filing with the U.S. Department of Health and Human Services’ Office for Civil Rights (HHS OCR), LCHD/CHC discovered on May 22, 2026 that some billing statements dated May 16, 2026 contained incorrect patient information due to a printing error. As a result, information associated with a patient’s account, or the account of a member of their household, may have been included on a billing statement sent to a different individual. The health department’s letter, signed by Privacy Officer Brenda Ruelas, states that the information involved may have included first names and account numbers, and specifically notes that no Social Security numbers or financial account information were included in the misdirected statements.
LCHD/CHC’s own letter states that upon discovering the error, the health department promptly investigated the incident, identified the affected individuals, and attempted to retrieve or securely destroy any misdirected billing statements where possible. The organization also says it has no evidence that any information has been misused and is notifying patients out of an abundance of caution, while recommending that recipients review any statements they receive and contact the health department if they notice unfamiliar or inaccurate information.
HHS OCR’s public breach portal lists this incident as affecting approximately 981 individuals, reported as an Unauthorized Access/Disclosure involving Paper/Films, with no business associate identified as being involved. Unlike a hacking or ransomware incident, this breach originated from an internal printing and mailing process error rather than an external cyberattack, but the notification and reporting obligations under HIPAA’s Breach Notification Rule apply the same way regardless of whether a breach results from a malicious intrusion or an internal administrative mistake.
Printing and mailing errors of this kind are a recurring category of healthcare data breach. Because billing systems often merge account and demographic data automatically before printing, a single software or process error can misdirect information for many patients in a single mailing run, as appears to have happened here. Even when the exposed information is limited, as LCHD/CHC states is the case in this incident, recipients whose names and account numbers were sent to a stranger may still face an increased risk of follow-up phishing attempts by people posing as the health department, an insurer, or a billing company in order to extract additional personal information.
When Did This Breach Occur?
The billing statements at the center of this incident were dated May 16, 2026. LCHD/CHC states it discovered the printing error on May 22, 2026, and the organization’s formal notification letter to affected patients is dated June 22, 2026. The federal HHS OCR filing reflects a breach submission date of July 17, 2026, which represents when the incident was formally reported to regulators rather than when the underlying error occurred or was discovered.
What Information Was Breached?
Per LCHD/CHC’s own notification letter, the information involved in this incident was limited to first names and account numbers. The health department’s letter explicitly states that no Social Security numbers or financial account information were included in the misdirected billing statements. This is a narrower scope of exposed information than many healthcare data breaches, which often involve more extensive medical or financial detail, though any unauthorized disclosure of a patient’s personal information tied to a healthcare account carries a privacy risk worth taking seriously.
What You Can Do
If you are a current or former patient or client of Lake County Health Department and Community Health Center, there are several steps you can take to help protect yourself:
- Review the notification letter from LCHD/CHC carefully, and contact the Privacy Officer with any questions.
- Check any billing statements or account correspondence you receive for information that appears inaccurate, unfamiliar, or belonging to someone else.
- If you receive a statement containing another patient’s information, securely destroy it or return it to the health department rather than copying, using, or further disclosing it.
- Monitor your account statements for any activity you do not recognize.
- Be cautious of unsolicited calls, texts, or emails claiming to be from the health department, an insurer, or a billing company asking you to verify personal information.
- Keep the notification letter and any related correspondence in case you need it later.
File a Data Breach Lawsuit Against Lake County Health Department and Community Health Center
If your personal information was compromised as a result of this data breach, you may be entitled to compensation for the harm it caused, including the time and expense of monitoring your accounts and the risk of identity theft or fraud going forward. Healthcare providers have a legal responsibility to implement reasonable safeguards, including in their billing and mailing processes, to protect the personal information entrusted to them, and a failure to do so can form the basis of a data breach lawsuit.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.