Woodlawn Hospital experienced a major data breach. On June 30, 2025, the hospital learned that its network had been accessed by an unauthorized actor. An investigation revealed that files were copied between June 25, 2025 and June 30, 2025. The hacked files contained sensitive information used for the operation of Woodlawn Hospital’s facilities.
The cybersecurity incident compromised both personally identifiable information (PII) and protected health information (PHI). Exposed information includes names, addresses, dates of birth, Social Security numbers, driver's license or state ID numbers, health insurance information and medical care information.
The data beach was disclosed to the U.S. Department of Health and Human Services on Aug. 25, 2025. Woodlawn Hospital also published a Notice of Data Security Incident on its website.
The total number of impacted individuals has not been released but is believed to include thousands of patients.
In addition to required state and federal disclosures, the hospital will notify impacted individuals by mail. The organization has also set up a dedicated assistance line at 877-332-1724, Monday through Friday from 8:00 a.m. to 8:00 p.m. Central Time.
If you believe your personal information may have been compromised in this breach:
For more information about the hospital, visit the Woodlawn Hospital website.
A breach notice means your personal details could be circulating far beyond the organization involved. One practical step is continuous monitoring: services such as Identity Defender (included with an ExpressVPN subscription) can automatically check dark-web markets, flag new credit-file activity, and request removal of your information from data-broker sites.
This kind of “early-warning system” can’t undo a breach, but it can help you spot misuse quickly and limit further exposure. ExpressVPN is offering 61% off, risk-free for 30 days, with ID Theft Insurance included and no extra cost for those who sign up for one or two years.