Back Teiss Eskenazi Health discloses phishing-related breach of Social Security, medical data
Eskenazi Health, a public safety-net health system in Indianapolis, disclosed a data breach that exposed patients’ Social Security numbers and medical information after a phishing attack gave an unauthorized individual access to an employee’s cloud-based work account.
According to the health system, the breach began when a trusted business ’s email account was compromised and used to send thousands of unauthorized emails to people in the ’s address book, including an Eskenazi Health employee. Because the message appeared to come from a known , the employee did not recognize it as suspicious, clicked a link presented as a secure document notification and completed the requested authentication process, giving the attacker access to the employee’s work account.
A forensic investigation found that the unauthorized access began around June 1, 2026, and continued until July 27, 2026, when Eskenazi Health discovered the suspicious activity and cut off access. A review of the affected account found it contained patient information, and the health system said the unauthorized individual may have accessed emails and attachments with sensitive data during that period.
The exposed information included names and other demographic or information, Social Security numbers, internal Eskenazi Health identifiers such as medical record numbers, health insurance and billing information, medical and treatment records, and sensitive health information including substance use disorder diagnosis and treatment records. The health system said the specific information affected varied by individual.
Eskenazi Health, the public hospital division of the Health & Hospital Corporation of Marion County, said it is leading the investigation on behalf of the corporation and its divisions. The health system said it has secured the affected account, implemented additional safeguards and is evaluating enhanced security controls and employee training to reduce the risk of similar incidents.
Eskenazi Health has begun notifying affected individuals and is offering identity protection services, including credit monitoring, at no cost; enrollment instructions are included in the notification letters. Individuals with questions can the health system’s response center at 833-919-4281, Monday through Friday from 9 a.m. to 9 p.m. Eastern time, or reach Equifax, Experian and TransUnion directly to review their credit files for suspicious activity.
Shamis & Gentile, a law firm specializing in data breach class actions, said it is investigating the Eskenazi Health breach.
Please take 30 seconds to register
Already have an account? Sign in
"If we think of usability and security as mutually exclusive - we have failed" - Jerrod Chong, Yubico
#teissLondon2018: On the internet, nobody knows you are a fridge
1 in 6 gamers disable all AV in the pursuit of the highest possible speeds
10 malicious Python Libraries discovered on PyPI Repository
126,000 affected by cyberattack on New Zealand patient portal Manage My Health
"If we think of usability and security as mutually exclusive - we have failed" - Jerrod Chong, Yubico
#teissLondon2018: On the internet, nobody knows you are a fridge
1 in 6 gamers disable all AV in the pursuit of the highest possible speeds
10 malicious Python Libraries discovered on PyPI Repository
126,000 affected by cyberattack on New Zealand patient portal Manage My Health
19-year-old claims he hacked into over 25 Tesla cars in 13 countries
2020 cybersecurity trends and resolutions
2025 in review: why cyber-security became a boardroom crisis
Closing the exposure window — unifying continuous threat exposure management
Trusting your AI agents
The blind spots in your stack - why fragmented data security fails
Winston House, 3rd Floor, Units 306-309, 2-4 Dollis park, London, N3 1HF
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
