Eskenazi Health, a public safety-net health system serving Indianapolis, has notified individuals that their personal and health information may have been exposed after an employee’s cloud-based work email account was compromised in a phishing attack. The health system is leading the investigation on behalf of the Health & Hospital Corporation of Marion County and its divisions.
Healthcare organizations that manage patients’ personal and medical records carry a responsibility to keep that information secure, particularly when it passes through employee email systems that can be targeted by phishing schemes.
Eskenazi Health’s Data Breach Investigation
According to Eskenazi Health, the incident began with a phishing attack that first compromised the email account of a trusted business contact. The unauthorized individual then used that contact’s compromised account to send thousands of unauthorized emails to people in the contact’s address book, including an Eskenazi Health employee. Because the phishing email appeared to come from a known and trusted contact, the employee did not recognize it as suspicious.
The email reportedly contained a link tied to what appeared to be a secure document notification. After the employee clicked the link and completed the requested authentication process, the unauthorized individual gained access to the employee’s cloud-based work account. Eskenazi Health’s forensic investigation determined that the unauthorized access began on June 1, 2026, and continued until July 27, 2026, when the health system discovered the suspicious activity and cut off access.
A review of the affected email account found that it contained patient information, including both personally identifiable information and protected health information.
This type of attack, known as business email compromise, remains one of the most common ways unauthorized parties gain a foothold inside otherwise well-defended organizations, because it exploits trust between known contacts rather than a technical vulnerability in a company’s own systems. Healthcare organizations are especially attractive targets for this kind of attack because employee email accounts routinely handle patient records, referrals, and billing information as a normal part of daily operations, meaning a single compromised mailbox can expose a large volume of sensitive data.
The combination of data types Eskenazi Health identified as exposed, Social Security numbers, internal medical record numbers, and details about substance use disorder diagnosis and treatment, is particularly sensitive. Beyond the risk of routine identity theft and fraudulent credit applications, exposure of substance use and treatment records carries a heightened risk of reputational and emotional harm, since this category of health information is subject to extra privacy protections under federal law precisely because of how damaging its disclosure can be.
Individuals notified of this incident should also be alert to follow-up phishing attempts. Scammers frequently use news of a real data breach to send additional phishing emails or phone calls impersonating the breached organization or a credit monitoring vendor, hoping to trick anxious recipients into handing over more personal information. Anyone contacted about this incident should independently verify communications using contact information from Eskenazi Health’s own notification letter or official website, rather than a link or number provided in an unsolicited message.
Breach-notification laws generally require organizations to determine the scope of an incident, including which individuals and what categories of information were involved, before sending notice letters, which is part of why several weeks or months can pass between when unauthorized access is discovered and when affected individuals are formally notified.
Business email compromise incidents like this one are also difficult for the compromised organization to detect quickly precisely because they abuse a legitimate, already-trusted communication channel rather than triggering the kinds of alerts that a malware infection or a direct network intrusion typically would. That is part of why a full forensic review, determining exactly which emails, attachments, and patient files an intruder accessed during a roughly eight-week window, takes considerably longer than simply resetting a compromised password.
Public safety-net health systems like Eskenazi Health also serve large, often vulnerable patient populations who may have fewer resources to absorb the practical fallout of identity theft or medical fraud, which makes the thoroughness of the credit monitoring and identity protection services offered in response to an incident like this an especially important part of how an affected organization mitigates harm to the people it serves.
When Did This Breach Occur?
Eskenazi Health’s investigation found that the unauthorized access to the compromised employee email account began on June 1, 2026, and continued until July 27, 2026, when the health system discovered the suspicious activity and cut off access.
What Information Was Breached?
The affected email account contained a mix of personally identifiable and protected health information. The personally identifiable information exposed included personal demographic and contact details, Social Security numbers, and Eskenazi Health internal identifiers such as medical record numbers. The protected health information exposed included health insurance and billing information, medical and treatment information, and sensitive health information such as substance use disorder diagnosis and treatment records.
What You Can Do
Eskenazi Health has notified affected individuals and is offering identity protection services, including credit monitoring, at no cost. If you received a notification letter, consider:
- Enrolling in the free identity theft protection and credit monitoring services offered by Eskenazi Health.
- Reviewing your medical, insurance, and financial statements for any unfamiliar activity.
- Placing a fraud alert or security freeze on your credit files with the major credit bureaus.
- Being cautious of unsolicited emails or calls referencing this breach.
- Contacting Eskenazi Health at 833-919-4281 (Monday through Friday, 9 a.m. to 9 p.m. EST) with questions about the incident.
File a Data Breach Lawsuit Against Eskenazi Health
If your personal or medical information was exposed in the Eskenazi Health data breach, you may have legal options to pursue compensation.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.