Kerber, Eck & Braeckel LLP Data Breach
Law Firm Network Server Breach Affects 134,918 Individuals
What happened in the Kerber, Eck & Braeckel LLP data breach?
The Kerber, Eck & Braeckel LLP data breach was reported on August 16, 2024 and affected 134,918 individuals. The breach type was Hacking/IT Incident involving Network Server. This breach occurred in Illinois. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Kerber, Eck & Braeckel LLP Breach Details
Healthcare Data Breach Report: Kerber, Eck & Braeckel LLP
Opening Summary
Kerber, Eck & Braeckel LLP, a law firm based in Illinois, experienced a significant data breach involving unauthorized access to its network server infrastructure. The breach was discovered and reported to the U.S. Department of Health and Human Services on August 16, 2024, affecting 134,918 individuals. The unauthorized access to the firm's network server represents a serious compromise of protected health information (PHI) and other sensitive personal data that the firm maintained in its capacity as a business associate to covered entities in the healthcare industry. This incident underscores the vulnerability of healthcare data stored across third-party service providers and the critical importance of strong cybersecurity measures in legal entities handling sensitive medical information.
Discovery and Response Timeline
The specific date of discovery and the timeline of the firm's response to this breach have not been publicly detailed in available records, though the August 16, 2024 submission date to HHS indicates the firm met its legal obligation to report the incident within the required timeframe under HIPAA Breach Notification Rule requirements. Upon discovery of the unauthorized access, Kerber, Eck & Braeckel LLP initiated an investigation to determine the scope and nature of the compromise. The firm's response likely included forensic analysis of the affected network server, identification of accessed data, and notification procedures for affected individuals as mandated by 45 CFR §164.400-414. As a business associate handling PHI on behalf of covered entities, the firm was required to notify both its covered entity clients and affected individuals without unreasonable delay and no later than 60 calendar days after discovery of the breach.
Technical Details of the Breach
The breach occurred on the firm's network server, which typically serves as a centralized repository for client files, communications, case management data, and other sensitive information. Network server compromises resulting from hacking or IT incidents generally indicate unauthorized remote access, potentially through vulnerabilities in internet-facing systems, compromised credentials, or exploitation of unpatched software. The classification as a "hacking/IT incident" suggests the breach resulted from deliberate unauthorized access rather than accidental loss or theft of physical media. Network servers in law firms handling healthcare matters commonly store extensive PHI including patient medical records, billing information, insurance details, and correspondence related to healthcare litigation or regulatory matters. The scope of access achieved by the unauthorized party remains unclear, but the large number of affected individuals (134,918) suggests either broad database access or compromise of multiple client files spanning numerous healthcare entities.
Organizational Context
Kerber, Eck & Braeckel LLP operates as a law firm in Illinois, likely providing legal services to healthcare organizations, medical practices, hospitals, and other covered entities or business associates. Law firms frequently serve as business associates under HIPAA when they handle PHI on behalf of healthcare clients—for example, in healthcare litigation, regulatory compliance matters, contract review, or administrative proceedings. The firm's role as a business associate means it was contractually obligated to implement and maintain appropriate administrative, physical, and technical safeguards to protect PHI, as outlined in the HIPAA Security Rule (45 CFR §§164.308-318). The breach of a network server suggests potential gaps in the firm's security infrastructure, access controls, or incident response capabilities. As a professional services firm handling sensitive healthcare information, the organization bore significant responsibility for protecting client data and maintaining the trust of healthcare entities that relied on its services.
Impact on Affected Individuals
Approximately 134,918 individuals had their personal information potentially exposed through the unauthorized access to Kerber, Eck & Braeckel LLP's network server. The specific categories of PHI exposed likely include names, addresses, dates of birth, medical record numbers, insurance information, diagnoses, treatment details, and potentially Social Security numbers or financial account information depending on the nature of the cases and matters handled by the firm. Individuals affected by this breach may have been patients of healthcare providers represented by the firm, parties to healthcare-related litigation, or subjects of healthcare regulatory matters. The notification process required the firm to provide affected individuals with details about the breach, the types of information compromised, steps the firm was taking to investigate and remediate the incident, and recommended actions for individuals to protect themselves from potential misuse of their information. The large scale of this breach—affecting over 134,000 individuals—represents a significant public health privacy incident requiring coordinated notification efforts across multiple healthcare organizations and jurisdictions.
HIPAA Compliance and Industry Context
Under the HIPAA Breach Notification Rule, any unauthorized access to unsecured PHI is presumed to be a breach unless the covered entity or business associate can demonstrate through a risk assessment that there is a low probability that the PHI has been compromised. Network server breaches resulting from hacking typically cannot meet this low-probability threshold, as they generally indicate successful unauthorized access. The Security Rule requires business associates like law firms to implement technical safeguards including access controls, encryption, audit controls, and integrity controls to protect ePHI (electronic PHI). The occurrence of this breach suggests potential deficiencies in one or more of these required safeguards. According to HHS data, hacking and IT incidents represent a significant portion of reported healthcare data breaches, particularly affecting organizations that handle PHI across networked systems. The involvement of a business associate in this breach highlights the extended risk landscape of healthcare data—information is not only at risk within covered entities' direct control but also across the broader ecosystem of service providers, vendors, and professional firms that handle sensitive health information. This incident serves as a reminder to healthcare organizations of the importance of rigorous business associate management, including regular security assessments, contractual safeguard requirements, and incident response coordination.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Kerber, Eck & Braeckel LLP Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries; consider placing a fraud alert or credit freeze to prevent unauthorized credit applications
Review healthcare and insurance statements carefully for unauthorized services, claims, or charges; contact providers and insurers immediately if suspicious activity is detected
Change passwords for all online accounts, particularly healthcare portals, insurance accounts, and financial institutions; use strong, unique passwords and enable multi-factor authentication where available
Consider enrolling in credit monitoring and identity theft protection services if offered by the firm; remain vigilant for phishing emails, calls, or texts requesting personal or health information
Document the breach and keep records of all notifications received; consult with a healthcare privacy attorney if concerned about potential misuse of exposed information or if identity theft occurs
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Illinois Breaches
Search all breaches reported in Illinois
Were You Affected?
Patients affected by large healthcare data breaches may be eligible for compensation through class action lawsuits.
Learn about data breach lawsuits