Eskenazi Health is notifying patients of a data breach after an employee’s cloud-based work account was compromised through a phishing email that appeared to come from a trusted business contact.
The Indianapolis-based health system discovered the unauthorized access July 27, according to a Sept. 25 notice. A forensic investigation determined the unauthorized access began June 3 and continued until Eskenazi Health terminated it July 27.
The incident began after the email account of one of Eskenazi Health’s business contacts was compromised and used to send thousands of unauthorized emails to individuals in the contact’s address book. An Eskenazi Health employee received one of the messages, which appeared to contain a secure document notification.
After the employee interacted with the link and completed the requested authentication process, an unauthorized individual gained access to the employee’s work account, according to the notice.
Eskenazi Health said the individual may have accessed certain emails and attachments stored in the account. Information that may have been involved varied by individual and could have included demographic and contact information, health insurance and billing information, medical record numbers, medical and treatment information, substance use disorder diagnosis and treatment information, and Social Security numbers.
The health system said it secured the affected account, implemented additional safeguards and is evaluating enhanced security controls and employee education. It is also offering free identity protection services to affected individuals.
Eskenazi Health is a public hospital division of the Health & Hospital Corporation of Marion County.