Were you recently affected by a data breach?

Our Hospice of South Central Indiana Data Breach

Our Hospice of South Central Indiana, a nonprofit hospice provider serving 22 Indiana counties, may have suffered a data breach after the ransomware group Storm claimed responsibility for an August 2026 cyberattack.

Our Hospice of South Central Indiana
Date of Breach: August 26, 2026 (claimed, unconfirmed)
CAU logo

Who was affected:

Clients of Our Hospice of South Central Indiana

Impacted Data:

Not yet confirmed. The ransomware group claiming responsibility has not disclosed specific data types, and Our Hospice of South Central Indiana has not issued an official notification.

Our Hospice of South Central Indiana, Inc., a nonprofit hospice and palliative care provider based in Columbus, Indiana, may have suffered a data breach after a ransomware group claimed responsibility for an attack on the organization’s computer systems. Attorneys are investigating whether current and former staff, patients, and their families had personal information exposed as a result.

Our Hospice of South Central Indiana’s Data Breach Investigation

Our Hospice of South Central Indiana, Inc. is a not-for-profit, community-based hospice organization that has served patients and families throughout south central Indiana since 1980. The organization provides end-of-life and palliative care across 22 counties in the region, working with patients, families, and referring healthcare providers to deliver hospice services in homes, care facilities, and its own inpatient settings.

On August 27, 2026, the dark web security site Ransomware.live reported that the hacker group known as Storm had listed Our Hospice of South Central Indiana on its leak site, claiming responsibility for a cyberattack estimated to have occurred the previous day, August 26, 2026. The cybersecurity blog HookPhish separately reported the same claim, noting that Storm asserted it had obtained files from the organization. As of this writing, Our Hospice of South Central Indiana has not publicly confirmed that a breach occurred, and no information has been made available describing what, if any, specific categories of data may have been affected.

Leak-site postings like this one are made by the ransomware or extortion group itself, and are often used as pressure during negotiations with a victim organization or as a way to advertise the group’s capabilities to future targets. Because the claim currently comes only from the attacker, it is considered unverified, and such claims can sometimes turn out to be exaggerated, based on data obtained elsewhere, or ultimately unsubstantiated. Independent confirmation typically requires either a formal investigation by the organization itself, a regulatory filing describing the incident in detail, or direct notification letters sent to those affected.

Hospice and other healthcare organizations have increasingly become targets for ransomware groups in recent years, in part because the sensitive personal and medical information they hold can be valuable to cybercriminals, and in part because many providers, particularly smaller nonprofit organizations, may have more limited cybersecurity budgets and staffing than larger hospital systems or insurers. Attackers frequently exploit these vulnerabilities to gain access to networks containing patient records, employee files, and other confidential data.

Attorneys working with ClassAction.org have opened an investigation into the reported incident and are seeking to hear from anyone affiliated with Our Hospice of South Central Indiana, including current and former staff, patients, and family members, who believes their personal information may have been put at risk. If the reported breach is confirmed and it is determined that Our Hospice of South Central Indiana failed to adequately protect the personal information entrusted to it, affected individuals may have grounds to pursue a class action lawsuit seeking compensation for any resulting harm, along with orders requiring the organization to improve its data security practices going forward.

Because no notification letters or official statements had been issued as of this writing, individuals who worked for, received care from, or otherwise interacted with Our Hospice of South Central Indiana are encouraged to watch for any communication from the organization and to take precautionary steps to protect their personal information in the meantime. This page will be updated if additional information about the scope of the incident becomes available.

When Did This Breach Occur?

Based on currently available reporting, the alleged cyberattack is estimated to have occurred on or around August 26, 2026, with the ransomware group Storm publicly claiming responsibility on August 27, 2026. Our Hospice of South Central Indiana has not issued its own public statement confirming a breach or specifying a discovery date, so these dates reflect the attacker’s own claims rather than a confirmed timeline from the organization. If Our Hospice of South Central Indiana later issues notification letters, those letters should be treated as the most accurate source of information about when the incident occurred and when it was discovered.

What Information Was Breached?

As of this writing, no specific categories of exposed data have been publicly confirmed or disclosed by Our Hospice of South Central Indiana or by independent investigators. The ransomware group claiming responsibility has not detailed exactly what types of information it obtained. Given that Our Hospice of South Central Indiana provides hospice and palliative care services, any records held by the organization could potentially include sensitive information such as patient names, contact details, medical and treatment information, insurance information, and employee personnel records, though none of this has been confirmed as compromised. This page will be updated with specific details as they become available or as official notifications are issued.

What You Can Do

If you are a current or former employee, patient, or family member of a patient of Our Hospice of South Central Indiana and are concerned about this reported incident, there are steps you can take now. Watch your mail and email for any official notification from the organization, and read any such notice carefully for details about what information may have been affected. Monitor your bank and credit card statements, as well as your credit reports, for unfamiliar activity. Consider placing a fraud alert or credit freeze with the major credit bureaus as a precaution. Be wary of unsolicited phone calls, texts, or emails referencing this incident, since scammers sometimes use news of a breach to attempt phishing schemes. If you receive medical bills, insurance statements, or benefit notices that you do not recognize, follow up with the relevant provider or insurer promptly.

File a Data Breach Lawsuit Against Our Hospice of South Central Indiana

If you are affiliated with Our Hospice of South Central Indiana and believe your personal information may have been put at risk in this reported data breach, you may be able to help start a class action lawsuit to recover compensation for the harm caused. A successful case could also require Our Hospice of South Central Indiana to strengthen the safeguards protecting the information entrusted to it. To learn more about the investigation and find out whether you may qualify to take part in a data breach lawsuit against Our Hospice of South Central Indiana, contact Class Action U today for a free case review.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Reported to the Vermont Attorney General's office in August 2026
Date of Breach: August 2026
Date of Breach: August 28, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.