DataBreachSearch.com
Investigation OpenIllinois AG filing · December 23, 2025

RUSH UNIVERSITY MEDICAL CENTER Confirms Data Breach Filing in 2025

RUSH UNIVERSITY MEDICAL CENTER has filed a data breach notice with the Illinois Attorney General, confirming an incident that may have exposed personal information. The notice, filed December 23, 2025, indicates an ongoing investigation into the security event. Individuals who received a notification letter should review it for details on how their data may have been affected.

State
Illinois
Reported
December 23, 2025

RUSH UNIVERSITY MEDICAL CENTER, a prominent academic healthcare provider, has officially reported a data security incident to the Illinois Attorney General. The filing, dated December 23, 2025, confirms that the medical center experienced a breach involving personal information it collects and stores. The specific nature of the breach has not been detailed in public records.

As a healthcare institution, RUSH UNIVERSITY MEDICAL CENTER manages extensive patient care, research, and clinical services. This requires the collection of highly sensitive personal information for treatment and billing purposes. Although the specific categories of data involved in this incident are unspecified in the public filing, individuals who received a notification should assume some of their personal information may have been affected.

The filing of this notice triggers a formal process to inform individuals whose information may have been compromised. If you received a data breach notification letter from RUSH UNIVERSITY MEDICAL CENTER, it means the organization has identified you as a potentially impacted individual. The letter should provide the most specific available information regarding the scope of the exposure.

It is important to carefully read any breach notification letter you receive from RUSH UNIVERSITY MEDICAL CENTER. This letter typically outlines the specific circumstances of the incident, confirms what personal information was involved, and may offer resources such as identity protection services.

Even if the specific data types are not listed, it is prudent to remain vigilant. Consider reviewing your account statements and credit reports for any unusual activity. Be wary of unsolicited communications, especially those asking for personal details. Promptly report any suspicious activity to the relevant financial institutions or authorities.

What to do if you were affected

These general steps can help limit the risk of identity theft and fraud after any data breach.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Related data breach cases