Skip to content
Eskenazi Health discloses phishing-related breach of Social Security, medical data

Eskenazi Health discloses phishing-related breach of Social Security, medical data

Teiss • September 30, 2026

Eskenazi Health, a public safety-net health system in Indianapolis, disclosed a data breach that exposed patients’ Social Security numbers and medical information after a phishing attack gave an unauthorized individual access to an employee’s cloud-based work account.

According to the health system, the breach began when a trusted business ’s email account was compromised and used to send thousands of unauthorized emails to people in the ’s address book, including an Eskenazi Health employee. Because the message appeared to come from a known , the employee did not recognize it as suspicious, clicked a link presented as a secure document notification and completed the requested authentication process, giving the attacker access to the employee’s work account.

A forensic investigation found that the unauthorized access began around June 1, 2026, and continued until July 27, 2026, when Eskenazi Health discovered the suspicious activity and cut off access. A review of the affected account found it contained patient information, and the health system said the unauthorized individual may have accessed emails and attachments with sensitive data during that period.

The exposed information included names and other demographic or information, Social Security numbers, internal Eskenazi Health identifiers such as medical record numbers, health insurance and billing information, medical and treatment records, and sensitive health information including substance use disorder diagnosis and treatment records. The health system said the specific information affected varied by individual.

Eskenazi Health, the public hospital division of the Health & Hospital Corporation of Marion County, said it is leading the investigation on behalf of the corporation and its divisions. The health system said it has secured the affected account, implemented additional safeguards and is evaluating enhanced security controls and employee training to reduce the risk of similar incidents.

Eskenazi Health has begun notifying affected individuals and is offering identity protection services, including credit monitoring, at no cost; enrollment instructions are included in the notification letters. Individuals with questions can the health system’s response center at 833-919-4281, Monday through Friday from 9 a.m. to 9 p.m. Eastern time, or reach Equifax, Experian and TransUnion directly to review their credit files for suspicious activity.

Shamis & Gentile, a law firm specializing in data breach class actions, said it is investigating the Eskenazi Health breach.

Please take 30 seconds to register

Already have an account? Sign in

"If we think of usability and security as mutually exclusive - we have failed" - Jerrod Chong, Yubico

#teissLondon2018: On the internet, nobody knows you are a fridge

1 in 6 gamers disable all AV in the pursuit of the highest possible speeds

10 malicious Python Libraries discovered on PyPI Repository

126,000 affected by cyberattack on New Zealand patient portal Manage My Health

"If we think of usability and security as mutually exclusive - we have failed" - Jerrod Chong, Yubico

#teissLondon2018: On the internet, nobody knows you are a fridge

1 in 6 gamers disable all AV in the pursuit of the highest possible speeds

10 malicious Python Libraries discovered on PyPI Repository

126,000 affected by cyberattack on New Zealand patient portal Manage My Health

19-year-old claims he hacked into over 25 Tesla cars in 13 countries

2020 cybersecurity trends and resolutions

2025 in review: why cyber-security became a boardroom crisis

Closing the exposure window — unifying continuous threat exposure management

Trusting your AI agents

The blind spots in your stack - why fragmented data security fails

Winston House, 3rd Floor, Units 306-309, 2-4 Dollis park, London, N3 1HF

Extracted Entities

Attack Types (1)

Companies (1)