Skip to main content
Jump to a category page

Meridian Health Plan of Illinois says a data breach exposed personal information for 21,027 people. The Medicaid managed-care plan didn’t notify members until three months after discovering the breach.

Meridian Health Plan of Illinois, a government-sponsored Medicaid managed-care plan, has confirmed that a data breach affected 21,027 individuals. According to HIPAAJournal, unauthorized access to Meridian’s provider portal was detected on April 28, 2026, and the company issued notification letters around July 23, 2026.

How the Breach Happened

Meridian detected unauthorized access to its provider portal on April 28, 2026, according to HIPAAJournal’s July 23, 2026 report. Meridian has confirmed the breach affected 21,027 individuals and says it has not identified any misuse of the exposed data.

What Information Was Exposed

According to HIPAAJournal’s reporting, the exposed information includes:

  • Member names
  • Contact information
  • Date of birth
  • Member ID numbers
  • Health plan name
  • Eligibility information
  • Claims information
  • Provider information

Meridian’s disclosure, as reported, does not list Social Security numbers or financial account information among the exposed data types.

Why the Three-Month Gap Matters

Meridian detected the unauthorized portal access on April 28, 2026, but notification letters did not go out until around July 23, 2026; roughly three months later. Meridian has not publicly explained the reason for the gap.

What Meridian Is Doing

It has not been confirmed whether Meridian is offering complimentary credit monitoring or identity protection to affected members. Anyone who received an individual notice letter should check it for details on any protective services available to them.

Do You Have Legal Options?

Government-sponsored health plans that collect member names, dates of birth, and health plan and claims information have a legal duty to protect it. A three-month gap between detecting unauthorized access and notifying members raises questions about whether Meridian met that duty. Members affected by this breach may have legal rights and remedies worth discussing with an attorney.

Contact the Data Breach Attorneys at Emery | Reddy today for a Free Case Review.

Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.

Much of the information involved in this incident may also qualify as Protected Health Information (PHI). PHI includes medical or healthcare-related data protected under federal and state privacy laws. When PHI is compromised, it can be misused for medical identity theft or insurance fraud.

Residents of California may be entitled to additional protections under the California Consumer Privacy Act (CCPA), which provides enhanced rights regarding the collection, use, and safeguarding of personal information.

FAQ

How many people were affected by the Meridian Health Plan of Illinois data breach?

Meridian has confirmed 21,027 individuals were affected.

What information was exposed in the breach?

According to HIPAAJournal’s reporting, the exposed information includes member names, contact information, dates of birth, Member ID numbers, health plan name, and eligibility, claims, and provider information. Social Security numbers and financial account information have not been reported as part of this breach.

Has Meridian found any evidence the data was misused?

No. As reported, Meridian has not identified any misuse of the exposed information as of the time of notice.

Why did it take Meridian three months to notify members?

Meridian detected unauthorized access to its provider portal on April 28, 2026, but notification letters did not go out until around July 23, 2026. Meridian has not explained the reason for the gap.

Is Meridian offering credit monitoring?

This has not been confirmed as of this writing. Check your individual notice letter, if you received one, for details on any protective services available to you.

What can I do to protect myself?

Consider these steps:

  • Review any Explanation of Benefits statements or Medicaid correspondence for services you don’t recognize
  • Watch for phishing emails, texts, or calls that mention this breach by name
  • Ask Meridian directly about any protective services available to you
  • Report anything suspicious to the FTC or your state attorney general

Has anyone sued Meridian Health Plan of Illinois over this breach?

Not as of this writing. No data-breach lawsuit against Meridian has been identified yet.

Do I have a legal claim?

Health plans that collect member information have a legal duty to keep it secure. If that duty was not met, affected individuals may be entitled to compensation. Emery | Reddy offers free, no-obligation case reviews. Call 206.207.8929 or visit www.emeryreddy.com to speak with a data breach attorney.

"Very friendly interview and intake process. I was informed thoroughly about the processes in obtaining a lawyer and was given ample time to make a decision on representation. I’m thankful for everyone’s help and looking forward to working with this Firm on my worker’s compensation claim."

- Darren A.

Receive a
FREE Case Review

Call Now