Skip to content

Eskenazi Health data breach exposes Social Security and medical data

Eskenazi Health data breach exposes Social Security and medical data

Eskenazi Health, a public safety-net health system in Indianapolis, has disclosed a data breach involving unauthorized access to an employee’s cloud-based work account after a phishing attack.

The health system is leading the investigation on behalf of the Health & Hospital Corporation of Marion County and its divisions. According to Eskenazi Health, the incident began with the compromise of an email account belonging to one of its trusted business contacts.

The attacker used that compromised account to send thousands of unauthorized emails to people in the contact’s address book, including an Eskenazi Health employee. Because the message appeared to come from a known contact, the employee didn’t recognize it as suspicious.

The phishing email contained a link presented as a secure document notification. After the employee opened the link and completed the requested authentication process, the attacker gained access to the employee’s cloud-based work account.

Unauthorized access continued from June 1 to July 27

A forensic investigation determined that unauthorized access to the account began on June 1, 2026, and continued until July 27. Eskenazi Health discovered suspicious activity on July 27 and terminated the unauthorized access.

The organization subsequently reviewed the affected account and found patient information among the emails and other material accessible through it. The information involved differs by individual.

Personally identifiable information potentially exposed in the incident included names and other demographic or contact information, Social Security numbers and internal Eskenazi Health identifiers such as medical record numbers.

The compromised account also contained protected health information. This included health insurance and billing information, medical and treatment records and sensitive health data, including substance use disorder diagnosis and treatment information.

Eskenazi Health notifies affected patients

Eskenazi Health has begun notifying individuals whose information was involved in the breach. The health system is offering identity protection services and credit monitoring at no cost to affected people.

Enrollment instructions are included in notification letters sent to individuals involved in the incident. Eskenazi Health also established a dedicated telephone line for questions about the breach.

Affected individuals can contact the response center at 833-919-4281 from Monday through Friday between 9 a.m. and 9 p.m. EST.

The incident shows how a compromise at one organization can be used to reach employees at another through trusted business relationships. In this case, the phishing message originated from a legitimate contact’s compromised email account, giving the attacker a route into an Eskenazi Health employee’s cloud-based work environment.