Skip to content
Author
PUBLISHED:
Getting your Trinity Audio player ready...

The Lake County Health Department recently notified some patients that the agency had sort of a data breach back in May. It wasn’t the first governmental hack and probably won’t be the last.

Apparently, some billing statements contained incorrect patient information due to a printing error, according to a Health Department statement. Officials stress that no financial account information or Social Security Administration numbers were involved, and no information has been misused.

That should come as a relief to those who use the Health Department and Community Health Center. Unlike some of us who have had various personal information swept into the dark web, or filling up data centers offshore, or deep in China, Iran, Nigeria or North Korea.

Welcome to the Data Breach Club, a widespread circle you’d prefer not to be included as a member. Like many of you, I have a stack of data collector notices of “security incidents” heaped in a drawer.

I was even asked to join a class-action lawsuit against an insurance company. I declined.

From that insurance company to medical centers to financial institutions, the pile of my cybersecurity memos grows annually. Companies urge us to go online to pay bills, withdraw funds and monitor spending.

But then come the data break-ins. Their privacy officers sincerely apologize for the breaches, and the companies offer free credit monitoring for a year or so with Experian, TransUnion and Equifax, the nation’s chief credit bureaus.

Which doesn’t help us if our private data is swirling digitally somewhere in the cloud, waiting to be used by bad actors and cyber-grifters years down the road. Usually, the firms proclaim that protecting my privacy is a high priority and they are taking steps to make sure similar incidents don’t recur.

Except, within the first six months of 2026, it’s estimated that 471.2 million data breach victim notices have been sent, according to the Identity Theft Resource Center’s 2026 Data Breach Report released last week. Forbes magazine reported that the number already outpaces breach notices for the entire year in 2025, which was 297.5 million.

Financial services data breaches are the most common, but health care, professional services, and manufacturing sectors have also been hit this year and in the past have been favorite targets of hackers. The largest incident so far this year was in May when Canvas, an education platform, was compromised. Forbes estimates some 275 million victim notices, 58% of the 2026 total victim notice count so far, have been sent to mainly collegians.

Most anti-scamming firms recommend theft protection services to help keep personal information safe and update consumers if a data breach is detected. Those companies charge for having peace of mind when it comes to cybersecurity incidents.

The county Health Department’s recent breach was the second for the agency. In September 2024, an unauthorized third party gained access to an employee’s email account, impacting a number of online accounts. No evidence of unauthorized transfer of data was found, but information that may have been involved included names, addresses, dates of birth, medications, phone numbers, email addresses, diagnosis/conditions and driver’s license numbers.

Also in 2024, the Illinois Secretary of State’s Office warned around 50,000 drivers that their personal data might have been exposed through a breach determined to have begun in Lake County.  A scammer infiltrated an official email account of a county government employee and sent two Illinois Secretary of State Office employees a phishing attempt.

Names, driver’s license numbers and SSNs likely were not compromised. Or maybe they were.

Most of us may never know if our privacy and information have been impacted through these data episodes. That is, until those warning letters come, sometimes months after the breach has occurred.

This despite state law requiring businesses and agencies that experience a data security breach to provide notice to the Illinois Attorney General’s Office, in addition to providing notification to affected residents and the types of personal information compromised in the breach. The date and timeframe of the breach, if known at the time of notification, also is required.

So what do these scammers do with our personal information — SSNs, driver’s license numbers, financial account data, medical records, health insurance IDs, biometric data and login credentials — once they get their hands on them? For starters, they could take over one’s financial accounts and loot them. Or open new credit accounts to buy lots of stuff.

That ancient warning caveat emptor, buyer beware, remains viable as we roam cyberspace and replace analog usage with our digital footprints.

Charles Selle is a former News-Sun reporter, political editor and editor. sellenews@gmail.com. X @sellenews