
Nearly 20,000 patients were affected by a data security breach that Healthcare insurance provider Meridian Health Plan of Illinois detected earlier this year.
Headquartered in Burr Ridge, Illinois, Meridian Health Plan of Illinois is a managed healthcare insurance organisation that provides Medicaid and Medicare-related health coverage and coordinated care services to eligible residents across Illinois. A subsidiary of Centene Corporation, the organisation focuses on government-sponsored healthcare programs and works with healthcare providers to improve access to medical, behavioral health, pharmacy, and support services.
In a data security incident notice published on its website, Meridian of Illinois stated that a security issue was identified on April 28 involving how certain providers were granted access to its online system. As a result, an unauthorised individual was able to view or download some members’ information. The healthcare insurance provider immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.
It also took steps to secure the affected systems including taking the affected accounts offline and notified relevant law enforcement authorities about the incident.
The investigation revealed that the compromised data included member names, Member ID numbers, dates of birth, contact information, and limited eligibility or claims-related details. The incident was reported to the U.S. Department of Health and Human Services where McLeod Health said it has identified at least 21,027 individuals impacted by the incident.
Following the discovery of the issue, Meridian of Illinois disabled the affected accounts, implemented additional security measures to help prevent similar incidents, reviewed its account approval processes, provided further staff training, and continued strengthening its systems to enhance overall security.
While the healthcare insurance provider said it found no evidence that the compromised information had been misused, it urged affected individuals to closely monitor their credit reports, account and benefit statements for any suspicious activity and to report potential identity theft or fraud to law enforcement, including local police and the state attorney general.
At the time of publication, no hacker group had publicly taken credit for the attack on Meridian of Illinois. The healthcare insurance provider also did not disclose details about the threat actor involved, the extent of the compromised data, or whether it had received any ransom demands.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543