Were you recently affected by a data breach?

Eskenazi Health Data Breach

Eskenazi Health, a public safety-net health system in Indianapolis, disclosed a data breach after a phishing attack compromised an employee’s email account, exposing patients’ Social Security numbers and sensitive medical information.

Eskenazi Health
Date of Breach: June 1, 2026 to July 27, 2026
CAU logo

Who was affected:

Clients of Eskenazi Health

Impacted Data:

Names, Social Security numbers, medical record numbers, health insurance and billing information, medical and treatment information, substance use disorder diagnosis and treatment records

Eskenazi Health, a public safety-net health system serving Indianapolis, has notified individuals that their personal and health information may have been exposed after an employee’s cloud-based work email account was compromised in a phishing attack. The health system is leading the investigation on behalf of the Health & Hospital Corporation of Marion County and its divisions.

Healthcare organizations that manage patients’ personal and medical records carry a responsibility to keep that information secure, particularly when it passes through employee email systems that can be targeted by phishing schemes.

Eskenazi Health’s Data Breach Investigation

According to Eskenazi Health, the incident began with a phishing attack that first compromised the email account of a trusted business contact. The unauthorized individual then used that contact’s compromised account to send thousands of unauthorized emails to people in the contact’s address book, including an Eskenazi Health employee. Because the phishing email appeared to come from a known and trusted contact, the employee did not recognize it as suspicious.

The email reportedly contained a link tied to what appeared to be a secure document notification. After the employee clicked the link and completed the requested authentication process, the unauthorized individual gained access to the employee’s cloud-based work account. Eskenazi Health’s forensic investigation determined that the unauthorized access began on June 1, 2026, and continued until July 27, 2026, when the health system discovered the suspicious activity and cut off access.

A review of the affected email account found that it contained patient information, including both personally identifiable information and protected health information.

This type of attack, known as business email compromise, remains one of the most common ways unauthorized parties gain a foothold inside otherwise well-defended organizations, because it exploits trust between known contacts rather than a technical vulnerability in a company’s own systems. Healthcare organizations are especially attractive targets for this kind of attack because employee email accounts routinely handle patient records, referrals, and billing information as a normal part of daily operations, meaning a single compromised mailbox can expose a large volume of sensitive data.

The combination of data types Eskenazi Health identified as exposed, Social Security numbers, internal medical record numbers, and details about substance use disorder diagnosis and treatment, is particularly sensitive. Beyond the risk of routine identity theft and fraudulent credit applications, exposure of substance use and treatment records carries a heightened risk of reputational and emotional harm, since this category of health information is subject to extra privacy protections under federal law precisely because of how damaging its disclosure can be.

Individuals notified of this incident should also be alert to follow-up phishing attempts. Scammers frequently use news of a real data breach to send additional phishing emails or phone calls impersonating the breached organization or a credit monitoring vendor, hoping to trick anxious recipients into handing over more personal information. Anyone contacted about this incident should independently verify communications using contact information from Eskenazi Health’s own notification letter or official website, rather than a link or number provided in an unsolicited message.

Breach-notification laws generally require organizations to determine the scope of an incident, including which individuals and what categories of information were involved, before sending notice letters, which is part of why several weeks or months can pass between when unauthorized access is discovered and when affected individuals are formally notified.

Business email compromise incidents like this one are also difficult for the compromised organization to detect quickly precisely because they abuse a legitimate, already-trusted communication channel rather than triggering the kinds of alerts that a malware infection or a direct network intrusion typically would. That is part of why a full forensic review, determining exactly which emails, attachments, and patient files an intruder accessed during a roughly eight-week window, takes considerably longer than simply resetting a compromised password.

Public safety-net health systems like Eskenazi Health also serve large, often vulnerable patient populations who may have fewer resources to absorb the practical fallout of identity theft or medical fraud, which makes the thoroughness of the credit monitoring and identity protection services offered in response to an incident like this an especially important part of how an affected organization mitigates harm to the people it serves.

When Did This Breach Occur?

Eskenazi Health’s investigation found that the unauthorized access to the compromised employee email account began on June 1, 2026, and continued until July 27, 2026, when the health system discovered the suspicious activity and cut off access.

What Information Was Breached?

The affected email account contained a mix of personally identifiable and protected health information. The personally identifiable information exposed included personal demographic and contact details, Social Security numbers, and Eskenazi Health internal identifiers such as medical record numbers. The protected health information exposed included health insurance and billing information, medical and treatment information, and sensitive health information such as substance use disorder diagnosis and treatment records.

What You Can Do

Eskenazi Health has notified affected individuals and is offering identity protection services, including credit monitoring, at no cost. If you received a notification letter, consider:

  • Enrolling in the free identity theft protection and credit monitoring services offered by Eskenazi Health.
  • Reviewing your medical, insurance, and financial statements for any unfamiliar activity.
  • Placing a fraud alert or security freeze on your credit files with the major credit bureaus.
  • Being cautious of unsolicited emails or calls referencing this breach.
  • Contacting Eskenazi Health at 833-919-4281 (Monday through Friday, 9 a.m. to 9 p.m. EST) with questions about the incident.

File a Data Breach Lawsuit Against Eskenazi Health

If your personal or medical information was exposed in the Eskenazi Health data breach, you may have legal options to pursue compensation.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: August 28, 2026
Date of Breach: Not publicly disclosed
Date of Breach: June 1, 2026 to July 27, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.