IHMC A.I CyberSecurity Scoring
IHMC
Company Information
Website:http://www.insightchicago.com
Employees number:328
Number of followers:3,096
NAICS:62
Industry Type:Hospitals and Health Care
Homepage:insightchicago.com
IHMC Risk Score (AI oriented)
Between 0 and 549
IHMCHospitals and Health Care
Updated:
03/06/2026
03/06/2026
489/1000
Critical
C
IHMC Global Score (TPRM)
xxxx
IHMCHospitals and Health Care
Score locked

IHMCCritical
Current Score
489C (CRITICAL)
01000
3 incidents
-180 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
505
JULY 2026
501
JUNE 2026
489
MAY 2026
482
APRIL 2026
478
MARCH 2026
469
FEBRUARY 2026
466
JANUARY 2026
460
DECEMBER 2025
452
NOVEMBER 2025
444
OCTOBER 2025
608
Ransomware
01 Oct 2025 • IHMC
Clarinda Regional Health Center and Insight Hospital & Medical Center: Iowa hospital warns 24,000+ people of data breach that leaked SSNs, medical and financial info
LockBit Ransomware Group Claims Responsibility for Iowa Hospital Data Breach Affecting 24,000 Patients
428
CRITICAL-180
CLAINS1780504049
LockBit Ransomware Group Claims Responsibility for Iowa Hospital Data Breach Affecting 24,000 Patients
Clarinda Regional Health Center (CRHC), a 47-bed hospital in southwest Iowa, has notified 24,341 individuals of a data breach exposing sensitive personal and medical information. The compromised data includes names, Social Security numbers, medical records, health insurance details, financial account numbers, taxpayer IDs, dates of birth, and driver’s license numbers.
The breach was discovered on December 15, 2025, though unauthorized access may have occurred as early as October 2025. The Russia-based ransomware group LockBit claimed responsibility for the attack on December 11, 2025, though CRHC has not confirmed the group’s involvement, and details of the breach including whether a ransom was paid remain unconfirmed. CRHC is offering affected individuals 12 months of free credit monitoring through TransUnion, with enrollment open for 90 days from the notice date.
LockBit, active since 2019, operates a ransomware-as-a-service (RaaS) model, allowing affiliates to deploy its malware in exchange for a share of ransom payments. In 2025, the group claimed 133 attacks, 12 of which were confirmed by targeted organizations, including another healthcare breach at Insight Hospital & Medical Center (Illinois) in August 2025. So far in 2026, LockBit has attributed 156 attacks, with 18 confirmed, including three healthcare incidents: Mt. Spokane Pediatrics (WA), Elmwood Healthcare (RI), and Consorzio Selenia (Italy).
The attack on CRHC is part of a broader surge in ransomware targeting U.S. healthcare providers. In 2025, 142 confirmed ransomware attacks on hospitals and clinics exposed 12.3 million patient records. In 2026, at least 16 additional attacks have compromised 66,400 records, with recent incidents involving groups like PEAR, Inc, Qilin, and Lynx. These attacks disrupt critical systems, forcing providers to cancel appointments, divert patients, or revert to manual record-keeping while facing ransom demands or prolonged downtime.
Founded in 1939, CRHC serves southwest Iowa through its main hospital and two family health centers in Villisca and Bedford. The full extent of the breach’s impact on operations remains unclear.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
SEPTEMBER 2025
608
AUGUST 2025
700
Ransomware
22 Aug 2025 • IHMC
Insight Hospital & Medical Center and Greater Pittsburgh Orthopedic Associates: Insight Chicago warns patients of data breach claimed by two ransomware groups
Data Breach at Insight Hospital & Medical Center in Chicago
604
CRITICAL-96
INSGRE1772045793
Cybercriminal Groups Claim Breach of Insight Hospital & Medical Center in Chicago
Insight Hospital & Medical Center in Chicago disclosed an August 2025 data breach exposing sensitive patient information, including names, Social Security numbers, dates of birth, state-issued ID numbers, financial account details, treatment records, and health insurance data. The hospital detected "unusual activity" in its network in September 2025, confirming unauthorized access between August 22 and September 11. Notably, the breach notice did not offer free credit monitoring or identity theft protection.
Two ransomware groups Termite and LockBit have separately claimed responsibility for the attack. Termite alleged it stole 360 GB of data, while LockBit, which previously targeted the hospital in December 2025, claimed 200 GB of stolen files. Neither claim has been verified, and Insight Chicago has not acknowledged either group’s involvement. Details about the breach method, ransom demands, or whether a payment was made remain undisclosed.
About the Threat Actors:
- LockBit, a well-established ransomware operation, claimed 133 breaches in 2025, with 10 confirmed by victims. Recent attacks include Mt. Spokane Pediatrics (January 2026) and Hennessy Advisors (March 2025).
- Termite, a newer group, has seven confirmed attacks in 2025, including one on Genea, an Australian healthcare firm.
Broader Impact on U.S. Healthcare:
Ransomware attacks on healthcare providers surged in 2025, with 122 confirmed incidents tracked by Comparitech. Recent examples include:
- Greater Pittsburgh Orthopedic Associates (August 2025, 56,954 affected) – claimed by RansomHouse.
- New Age Dermatology (December 2025) – ransomware attack.
- Virginia Urology (November 2025, 1,893 affected) – claimed by MS13-089.
- Pecan Tree Dental (2026, 13,300 affected) – claimed by Sinobi.
- University of Mississippi Medical Center (2026) – ongoing recovery.
Such attacks disrupt critical systems, forcing hospitals to cancel appointments, divert patients, or revert to manual processes, endangering patient safety and data security.
About Insight Chicago:
Formerly Mercy Hospital and Medical Center, the 414-bed facility was acquired and rebranded by Insight Health Systems in 2021.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
AUGUST 2025
763
Breach
01 Aug 2025 • IHMC
Insight Hospital and Medical Care Center: Insight Hospital patients advised to take precautions after last summer's data breach
Bronzeville Hospital Data Breach Exposes Patient Information After Nine-Month Delay
699
CRITICAL-64
INS1776227401
Bronzeville Hospital Data Breach Exposes Patient Information After Nine-Month Delay
A data breach at Insight Hospital and Medical Care Center in Chicago’s Bronzeville neighborhood has raised concerns after patients were notified nearly nine months after the incident occurred. The breach, which took place between August and September 2023, potentially exposed sensitive patient information, including Social Security numbers, financial account details, and health insurance data.
Local community leader and 2nd District police councilor Alexander Perez expressed frustration over the delayed notification, particularly for vulnerable patients such as elderly residents on fixed incomes or those living in nearby senior facilities who may have been unaware their data was compromised. Perez highlighted the lost opportunity for proactive measures to mitigate harm, noting that hospitals, as trusted healthcare providers, should prioritize preventative security.
Insight Hospital acknowledged the breach in a recent statement, confirming that unauthorized individuals accessed their systems. The hospital is conducting a review to determine the full scope of exposed data and plans to notify affected individuals once the investigation is complete. In the meantime, they have advised patients to monitor their credit reports, place fraud alerts, freeze their credit files, and review account statements for suspicious activity.
Cybersecurity expert Scott Schober warned that compromised data could be exploited for fraudulent insurance claims or identity theft, with risks persisting for up to two years. He also noted that smaller hospitals often lack the resources for robust cybersecurity, making them prime targets for attacks.
While Insight Hospital stated that only a "limited amount" of patient information was compromised, the exact number of affected individuals and the timeline of notifications remain unclear. The incident underscores the ongoing challenges of data security in healthcare, particularly for smaller institutions.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for IHMC ??
What was IHMC's A.I Rankiteo Cyber Score in July 2026 ??
What was IHMC's A.I Rankiteo Cyber Score in June 2026 ??
What was IHMC's A.I Rankiteo Cyber Score in May 2026 ??
What was IHMC's A.I Rankiteo Cyber Score in April 2026 ??
What was IHMC's A.I Rankiteo Cyber Score in March 2026 ??
What was IHMC's A.I Rankiteo Cyber Score in February 2026 ??
What was IHMC's A.I Rankiteo Cyber Score in January 2026 ??
What was IHMC's A.I Rankiteo Cyber Score in December 2025 ??
What was IHMC's A.I Rankiteo Cyber Score in November 2025 ??
What was IHMC's A.I Rankiteo Cyber Score in October 2025 ??
What was IHMC's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on IHMC's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with IHMC ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view IHMC's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?