Indiana Hemophilia and Thrombosis Center, Inc. Data Breach
Indiana Hemophilia Center Email Breach Affects 2,575 Patients
What happened in the Indiana Hemophilia and Thrombosis Center, Inc. data breach?
The Indiana Hemophilia and Thrombosis Center, Inc. data breach was reported on March 4, 2022 and affected 2,575 individuals. The breach type was Hacking/IT Incident involving Email. This breach occurred in Indiana. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Indiana Hemophilia and Thrombosis Center, Inc. Breach Details
On March 4, 2022, Indiana Hemophilia and Thrombosis Center, Inc. reported a significant data breach involving unauthorized access to patient email systems. The breach, classified as a hacking or IT incident, compromised the email accounts used by the organization to communicate with and manage patient information. This incident represents a serious breach of patient privacy affecting over 2,500 individuals who sought specialized care for hemophilia, thrombosis, and related blood disorders at the Indiana-based facility.
Company Response
Upon discovery of the unauthorized access to their email systems, Indiana Hemophilia and Thrombosis Center initiated an immediate investigation to determine the scope and nature of the breach. The organization worked to secure their email infrastructure, prevent further unauthorized access, and identify all individuals whose protected health information (PHI) may have been exposed. The breach was reported to the Indiana Attorney General and affected individuals on March 4, 2022, in compliance with HIPAA Breach Notification Rule requirements, which mandate notification without unreasonable delay and no later than 60 calendar days after discovery of a breach.
Specific Details
The breach occurred within the organization's email system, which typically serves as a central repository for patient communications, appointment scheduling, clinical notes, test results, and other sensitive healthcare information. Email-based breaches of this nature often result from compromised credentials, phishing attacks, malware infections, or exploitation of unpatched email server vulnerabilities. The fact that this incident was classified as a hacking or IT incident suggests that unauthorized actors gained access through technical means rather than physical theft or loss of devices. Email systems in healthcare settings are particularly attractive targets for threat actors because they contain a comprehensive record of patient interactions and often include sensitive clinical and personal information in message bodies and attachments.
Organizational Context
Indiana Hemophilia and Thrombosis Center, Inc. is a specialized healthcare provider focused on the diagnosis, treatment, and management of hemophilia, thrombosis, and other blood clotting disorders. These conditions require ongoing specialized care, regular monitoring, and frequent patient-provider communication. The center serves patients throughout Indiana and potentially surrounding regions who require expert hematological care. As a specialized treatment center, the organization maintains detailed medical records including genetic testing results, treatment protocols, medication histories, and other highly sensitive clinical information specific to rare blood disorders.
Number of People Affected
The breach impacted 2,575 individuals who were patients of or had contact with Indiana Hemophilia and Thrombosis Center. This patient population includes both pediatric and adult patients with hemophilia and related conditions, many of whom require lifelong specialized care and monitoring. The affected individuals represent a significant portion of the center's patient base, indicating that the email compromise was substantial in scope.
Personal Information Involved
Based on the nature of email-based breaches at healthcare facilities, the compromised information likely included:
- Patient names and contact information (addresses, phone numbers, email addresses)
- Medical record numbers and patient identification numbers
- Insurance information (policy numbers, group numbers, subscriber information)
- Clinical information (diagnoses, treatment plans, medication lists, dosages)
- Test results and laboratory values (clotting factor levels, genetic testing results)
- Appointment scheduling information and visit notes
- Provider communications regarding patient care and treatment recommendations
- Potentially Social Security numbers if included in patient registration or insurance documentation
- Financial information related to billing and payment arrangements
The specific data elements exposed depend on what information was stored within the compromised email accounts and what attachments or forwarded messages contained patient PHI.
Likely Risks to Patients
Patients affected by this breach face several significant risks:
Identity Theft and Fraud: With access to names, addresses, dates of birth, and potentially Social Security numbers, threat actors could attempt to open fraudulent accounts, apply for credit, or commit medical identity theft using the patient's information.
Medical Identity Theft: Criminals could use stolen medical information to obtain prescription medications, seek medical treatment under a patient's name, or submit fraudulent insurance claims, potentially affecting the patient's medical record and insurance coverage.
Insurance Fraud: Access to insurance policy numbers and subscriber information enables threat actors to file false claims or manipulate coverage information.
Targeted Phishing and Social Engineering: Threat actors with knowledge of a patient's medical condition, provider relationships, and clinical details could craft highly convincing phishing emails or social engineering attacks targeting the patient or their family members.
Stigma and Discrimination: Hemophilia and thrombosis conditions are relatively rare, and disclosure of this information could lead to discrimination in employment, insurance, or social contexts if the information is misused or publicly disclosed.
Medication Diversion: Knowledge of specific medications and dosages could enable criminals to attempt prescription fraud or medication diversion schemes.
Recommended Actions for Patients
-
Monitor Credit Reports and Place Fraud Alerts: Obtain free credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) through AnnualCreditReport.com and review them carefully for unauthorized accounts or inquiries. Consider placing a fraud alert or credit freeze with the bureaus to prevent unauthorized credit applications.
-
Monitor Medical Records and Insurance Statements: Regularly review Explanation of Benefits (EOB) statements from your insurance provider and request copies of your medical records to verify that no unauthorized treatment or claims have been submitted in your name. Contact your healthcare providers immediately if you notice any discrepancies.
-
Change Email Passwords and Enable Multi-Factor Authentication: Change the password for any email accounts used to communicate with Indiana Hemophilia and Thrombosis Center or other healthcare providers. Enable multi-factor authentication (MFA) on all email and online healthcare accounts to prevent unauthorized access even if passwords are compromised.
-
Remain Vigilant Against Phishing and Social Engineering: Be cautious of unsolicited emails, phone calls, or messages claiming to be from healthcare providers, insurance companies, or financial institutions. Do not click links or download attachments from suspicious emails, and verify requests for information by contacting organizations directly using phone numbers or websites you know to be legitimate. Threat actors may use knowledge of your medical condition to craft convincing fraudulent communications.
Industry Context
Email-based breaches represent a significant and growing threat in healthcare. According to HIPAA breach notification data, email compromise incidents consistently rank among the most common causes of healthcare data breaches, often resulting from phishing attacks, credential compromise, or exploitation of email server vulnerabilities. The HIPAA Breach Notification Rule requires covered entities and business associates to notify affected individuals, the media (if more than 500 residents of a state are affected), and the Secretary of Health and Human Services of breaches of unsecured PHI.
Specialized healthcare providers like hemophilia treatment centers face particular challenges in protecting patient data because they maintain detailed clinical information about rare conditions and often communicate frequently with patients via email regarding treatment protocols and medication management. The relatively small patient population for these specialized conditions also means that affected individuals may be more easily identifiable if data is disclosed, increasing privacy risks.
Patients should take the recommended protective actions seriously and consider enrolling in any credit monitoring or identity theft protection services that may be offered by the healthcare provider as part of their breach response efforts. Ongoing vigilance and monitoring of financial and medical accounts is essential for detecting and responding quickly to any fraudulent activity resulting from this breach.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Indiana Hemophilia and Thrombosis Center, Inc. Breach
Monitor credit reports from all three bureaus (Equifax, Experian, TransUnion) through AnnualCreditReport.com and place fraud alerts or credit freezes to prevent unauthorized credit applications
Review Explanation of Benefits (EOB) statements and medical records regularly to detect unauthorized treatment or insurance claims; contact providers immediately if discrepancies are found
Change passwords for email accounts used to communicate with healthcare providers and enable multi-factor authentication (MFA) on all email and online healthcare accounts
Remain vigilant against phishing and social engineering attacks; verify requests for information by contacting organizations directly using known phone numbers or websites rather than responding to unsolicited communications
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Indiana Breaches
Search all breaches reported in Indiana