An Illinois Dermatology Practice Was Hit by Ransomware. What Suburban Chicago Practices Should Learn
- Errol Janusz
- Jul 11
- 2 min read

According to public breach notices and news reporting, a dermatology group in southern Illinois discovered unusual activity on its network in late November 2025. The investigation that followed found that files containing patient information, including names, dates of birth, Social Security numbers, and medical record numbers, had potentially been accessed, with roughly 160,000 people affected and reporting linking the attack to a ransomware group. Patient notifications began in the spring, and class-action attorneys are already circling. Here is what that sequence should teach every practice in the western and northwestern suburbs.
The timeline is the lesson
Read it again: intrusion discovered in November, scope determined in March, notifications in April. Months of investigation, legal exposure, and patient anxiety, all downstream of the first quiet hours when an attacker moved unnoticed. The cheapest moment to stop a breach is before the encryption starts, which is exactly the job of endpoint detection and response: flag the behavior, isolate the machine, end the story early.
Small practices are not too small
Attackers do not check your headcount. Automated tools find exposed remote access and unpatched systems wherever they exist, and a practice holding Social Security numbers and medical records is a payday regardless of size. Assuming you are beneath notice is the most expensive security posture in healthcare.
The clock starts before you are ready
Illinois law generally requires breach notification within 45 days, and HIPAA sets a 60-day outer limit for notifying affected individuals. Those clocks run while you are still figuring out what happened, which is why the written incident plan, the tested backups, and the relationship with someone who has done this before all need to exist on the boring days.
The other kind of breach: nobody hacked anything
In a separate Illinois disclosure this year, a state agency reported that data tied to hundreds of thousands of people had sat on a publicly viewable website for years because of a privacy-settings mistake. No attacker required. Misconfigured sharing settings are the quiet cousin of ransomware, and a periodic risk assessment exists to catch exactly that class of error before a journalist does.
What to do this week
Confirm MFA covers every account. Ask who is actually watching your endpoint alerts. Ask when a restore was last tested. If any answer is a shrug, call 847.737.8111. The complimentary onsite evaluation gives a practice straight answers before the timeline above becomes yours.



Comments