
Eskenazi Health, a public safety-net health system in Indianapolis, disclosed a data breach involving unauthorized access to an employee's cloud-based work account.
The health system posted a notice about the security incident on its website, stating it is leading the investigation on behalf of the Health & Hospital Corporation of Marion County and its divisions.
The breach resulted from a phishing attack that compromised an employee's cloud-based work account. The email account of a trusted business contact had first been compromised by an unauthorized individual. The individual then used the compromised contact's account to send thousands of unauthorized emails to people in the contact's address book, including an Eskenazi Health employee.
Because the phishing email appeared to come from a known and trusted contact, the employee did not recognize it as suspicious. The email contained a link tied to what appeared to be a secure document notification. After the employee clicked the link and completed the requested authentication process, the unauthorized individual gained access to the employee's cloud-based work account.
The forensic investigation determined that the unauthorized access began on June 1, 2026, and continued until July 27, 2026. On that date, Eskenazi Health discovered the suspicious activity and cut off the unauthorized access.
A review of the affected email account found that it contained patient information.
The types of personally identifiable information exposed included personal demographic and contact information, Social Security numbers and Eskenazi Health internal identifiers such as medical record numbers.
The types of protected health information exposed included health insurance and billing information, medical and treatment information and sensitive health information such as substance use disorder diagnosis and treatment records.
Eskenazi Health has notified affected individuals and is offering identity protection services, including credit monitoring, at no cost. Instructions on how to enroll in the identity theft protection program are included in the notification letters sent to those affected.
Individuals with questions about the incident can call 833-919-4281, Monday through Friday, 9 a.m. to 9 p.m. EST.








.webp)
.webp)
.webp)

.webp)
.webp)
.webp)
.webp)