Eskenazi Health Suffered Data Breach From Phishing
A phishing campaign targeting an Indianapolis healthcare employee exposed sensitive patient information for eight weeks.
Updated on Sept. 29, 2026 in Cybersecurity

Live Poll
Do you trust your local healthcare providers to adequately protect your sensitive personal and medical data?
Eskenazi Health reported that a phishing attack granted unauthorized access to a cloud-based account from June 1, 2026, through July 27, 2026. The incident exposed protected health information including Social Security numbers, billing details, and medical records.
Why it matters
The breach highlights the persistent vulnerability of healthcare systems to credential-harvesting attacks that bypass standard email security filters. It underscores the critical need for robust identity authentication protocols in protecting patient confidentiality within the Indianapolis health network.
The incident lasted from June 1, 2026, to July 27, 2026, covering a duration of 56 days. The breach resulted from a compromised business contact email that facilitated an unauthorized authentication event.
The players
Eskenazi Health
An Indianapolis-based healthcare system providing comprehensive medical services and inpatient care.
The details
The breach occurred when an employee interacted with a phishing link received from a compromised business contact, subsequently completing an authentication process that granted the attacker cloud access. This access permitted the exposure of sensitive data, including medical record numbers, demographic information, insurance details, and records related to substance use disorder treatment.
Timeline
June 1, 2026: Unauthorized access to the employee account began.
July 27, 2026: Unauthorized access terminated after discovery.
The Tech Race
The incident follows a pattern of HIPAA-regulated entities struggling to prevent credential-based access to cloud-stored protected health information. This breach underscores the ongoing industry race to harden identity infrastructure against increasingly sophisticated phishing vectors.
Affected individuals in Indianapolis can contact the response center at 833-919-4281 for assistance with credit monitoring services. The center operates from 9 a.m. to 9 p.m. EST to address patient concerns regarding their exposed health and billing data.
The takeaway
Healthcare providers remain high-value targets for attackers utilizing social engineering to compromise cloud-based identity credentials. Patients should monitor their financial and medical statements closely for fraudulent activity in the months following this incident.
Further reading
For broader trends in digital security and threat intelligence, see Cybersecurity.
Source note: This article includes information reported by Beinsure: Insurance & InsurTech Media Market Intelligence Platform.
Live Poll
Do you trust your local healthcare providers to adequately protect your sensitive personal and medical data?







