Indiana University Health email compromise exposed patient records
- Organization
- Indiana University Health
- Exploit
- Credential Compromise
- Industry
- Healthcare
Indiana University Health disclosed in January 2025 that an unauthorized party had access to an employee's email account between August 27 and October 2, 2024. The health system said it detected unusual activity on the account on November 8 and engaged an outside forensics firm to determine what had been reached.
The review found the mailbox held patient information. Data that may have been exposed included names, addresses, ages, medical record numbers, diagnoses and other limited treatment details. IU Health said Social Security numbers were involved for a smaller subset of people.
The system began mailing notification letters on January 2, 2025 and opened a dedicated call center to field questions. Individuals whose Social Security numbers were affected were offered 12 months of complimentary credit monitoring. IU Health said it had secured the compromised account and was continuing to implement additional safeguards.
IU Health did not publicly state how many people were affected. It is the largest health system in Indiana, running hospitals and clinics across the state.