Did 240 have a data breach?
Answer
Yes. 240 reported a data breach to the Indiana Attorney General on February 18, 2026.
View the official filingWhat the filing says
- Reported to
- Indiana Attorney General
- Filing date
- February 18, 2026
- Breach date
- June 17, 2025
- People affected
- Not stated in the filing
Information involved
- Full Name
- Date of Birth
- Social Security Number
- Medical Record Number
- Health Insurance ID Number
- Diagnosis and Treatment Information
- Prescription Information
- Provider and Treatment Dates
In plain terms
Digital health solutions provider 240 reported a data breach in Indiana in February 2026. The incident exposed sensitive personal and health information, including Full Name, Date of Birth, and Social Security Number, putting affected individuals at risk of identity theft and medical fraud.
240, a company operating in the digital health and wellness sector, formally reported a data breach to the Indiana Attorney General on February 18, 2026. The company provides software solutions, telemedicine platforms, and patient management systems, and routinely handles a significant volume of protected health information and sensitive consumer records.
The breach, which occurred on June 17, 2025, involved an unspecified type of cybersecurity incident impacting 240's network infrastructure. The company confirmed that individuals residing in Indiana and potentially elsewhere were affected by the compromise of their personal data.
The types of data reported as exposed include Full Name, Date of Birth, Social Security Number, Medical Record Number, Health Insurance ID Number, Diagnosis and Treatment Information, Prescription Information, and Provider and Treatment Dates. The exposure of such sensitive personal and health records carries significant risks for those impacted.
Individuals who received a notification letter from 240 should review the document carefully for specific details about the incident. It is advisable to remain vigilant for signs of identity theft or fraud, monitor financial accounts and credit reports, and consider placing a fraud alert or security freeze on credit with the major credit bureaus.
Commonly recommended next steps
Freeze your credit
Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.
Check for medical identity theft
Review the Explanation of Benefits statements from your health insurer for services or claims you never received, which can signal misuse of your medical identity.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Look up another company
Other breaches reported in Indiana
- Teamsters Local 17Yes — reportedIndiana
- BankYes — reportedIndiana
- PeoplesBankYes — reportedIndiana · October 8, 2026
- McKenzie Creative BrandsYes — reportedIndiana · September 30, 2026
- MEBS Global ReachYes — reportedIndiana · September 30, 2026
- Midvale Indemnity and American Family Connect Insurance CompanyYes — reportedIndiana · September 30, 2026
- American Motorcyclist AssociationYes — reportedIndiana · September 30, 2026
- Nishiyamato AcademyYes — reportedIndiana · September 30, 2026
- Deer Management Co. LLC dba Bessemer Venture PartnersYes — reportedIndiana · September 30, 2026
- 9World Acceptance CorporationYes — reportedIndiana · September 30, 2026
DataBreachSearch.com reports what was filed with state regulators. It is not legal advice, is not a law firm, and is not affiliated with any government agency or with 240.