Did 2Sunrise Company have a data breach?
Answer
Yes. 2Sunrise Company reported a data breach to the Indiana Attorney General on July 28, 2026.
View the official filingWhat the filing says
- Reported to
- Indiana Attorney General
- Filing date
- July 28, 2026
- Breach date
- April 23, 2026
- People affected
- Not stated in the filing
Information involved
- Full Name
- Date of Birth
- Social Security Number
- Medical Record Number
- Health Insurance ID Number
- Diagnosis and Treatment Information
- Home Address
- Phone Number
In plain terms
Based in Indiana, 2Sunrise Company operates as an integrated behavioral health and elder-care services provider, offering specialized residential care, outpatient wellness programs, and specialized therapeutic support. Because of the comprehensive care model it provides, the organization routinely collects, processes, and stores vast amounts of deeply sensitive personal information concerning its patients, residents, and program participants. This data typically includes comprehensive clinical histories, diagnostic records, treatment plans, and administrative details necessary for coordinating specialized care and processing insurance claims. Consequently, 2Sunrise Company functions as a critical repository for highly private health and demographic data, creating a profound duty to maintain robust, impenetrable cybersecurity safeguards.
In 2026, 2Sunrise Company formally reported a significant cybersecurity incident to the Indiana Attorney General, alerting regulators and the public to a compromise of its internal network infrastructure. Security incidents affecting healthcare and elder-care providers of this scale frequently involve sophisticated external cyberattacks, such as unauthorized intrusions into centralized electronic health record (EHR) databases, ransomware deployments designed to encrypt critical files, or vulnerabilities exploited within third-party vendor software supply chains. When threat actors successfully breach these proprietary environments, they often gain unrestricted access to operational servers containing decades of confidential patient and employee files, signaling potential systemic vulnerabilities in network monitoring and access controls.
The data compromised in the 2Sunrise Company breach reportedly spans multiple categories of sensitive information, each presenting severe, long-term risks to affected individuals. The exposure of clinical records, treatment histories, and health insurance details creates immediate vulnerabilities to medical identity theft, where bad actors can fraudulently obtain prescription drugs or bill insurance providers for unauthorized medical procedures. Furthermore, the concurrent exposure of foundational personally identifiable information—such as full names, dates of birth, and Social Security numbers—exposes victims to sweeping financial fraud, including unauthorized credit applications, tax refund theft, and account takeover schemes that can take years to remediate.
Under federal and state law, including the Health Insurance Portability and Accountability Act (HIPAA) and the Indiana Disclosure of Security Breach Law, 2Sunrise Company had strict legal obligations to implement and maintain comprehensive administrative, physical, and technical safeguards to protect electronic protected health information (ePHI) and personal data. These regulatory mandates require continuous vulnerability assessments, stringent access controls, and rapid incident response protocols. The occurrence of a breach of this magnitude strongly suggests potential failures in upholding these statutory duties, raising serious legal questions regarding whether the organization maintained adequate cybersecurity measures to prevent unauthorized data exfiltration.
If you received a data breach notification letter from 2Sunrise Company, it serves as formal legal acknowledgment that your private information was compromised due to inadequate security practices. Under consumer protection and privacy jurisprudence, the receipt of such a letter provides the legal standing necessary to participate in a class action lawsuit aimed at holding the company accountable. Importantly, victims are not required to demonstrate immediate financial loss or actualized identity theft to pursue legal remedies; the increased risk of future harm and the invasion of privacy are actionable injuries. Our firm investigates these matters on a contingency fee basis, meaning you pay nothing out of pocket and owe no legal fees unless we successfully recover compensation on your behalf.
Commonly recommended next steps
Freeze your credit
Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.
Check for medical identity theft
Review the Explanation of Benefits statements from your health insurer for services or claims you never received, which can signal misuse of your medical identity.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Look up another company
Other breaches reported in Indiana
- Teamsters Local 17Yes — reportedIndiana
- BankYes — reportedIndiana
- PeoplesBankYes — reportedIndiana · October 8, 2026
- McKenzie Creative BrandsYes — reportedIndiana · September 30, 2026
- MEBS Global ReachYes — reportedIndiana · September 30, 2026
- Midvale Indemnity and American Family Connect Insurance CompanyYes — reportedIndiana · September 30, 2026
- American Motorcyclist AssociationYes — reportedIndiana · September 30, 2026
- Nishiyamato AcademyYes — reportedIndiana · September 30, 2026
- Deer Management Co. LLC dba Bessemer Venture PartnersYes — reportedIndiana · September 30, 2026
- 9World Acceptance CorporationYes — reportedIndiana · September 30, 2026
DataBreachSearch.com reports what was filed with state regulators. It is not legal advice, is not a law firm, and is not affiliated with any government agency or with 2Sunrise Company.