DataBreachSearch.com

Did Graham County Hospital have a data breach?

Answer

Yes. Graham County Hospital reported a data breach to the Indiana Attorney General on September 14, 2026.

View the official filing

What the filing says

Reported to
Indiana Attorney General
Filing date
September 14, 2026
Breach date
December 18, 2025
People affected
Not stated in the filing

Information involved

  • Full Name
  • Date of Birth
  • Social Security Number
  • Medical Record Number
  • Health Insurance ID Number
  • Diagnosis and Treatment Information
  • Prescription Information
  • Provider and Treatment Dates

In plain terms

Graham County Hospital in Indiana officially reported a data breach on September 14, 2026, stemming from an incident on December 18, 2025. This breach exposed various sensitive patient details, including names, dates of birth, Social Security Number, and medical information, putting affected individuals at risk of identity and medical fraud.

Graham County Hospital, located in Indiana, reported a data security incident to regulators on September 14, 2026. This public filing indicated that an unauthorized compromise of its internal network infrastructure occurred on December 18, 2025.

The official report specifies that the breach resulted in the exposure of several categories of sensitive information. These categories include Full Name, Date of Birth, Social Security Number, Medical Record Number, Health Insurance ID Number, Diagnosis and Treatment Information, Prescription Information, and Provider and Treatment Dates.

Exposure of such detailed personal and health information can lead to significant risks for those affected. Unlike financial accounts which can often be reissued, compromised medical data cannot be easily changed or cancelled. This type of information can be misused for medical identity theft, where unauthorized services are obtained under a victim's name, potentially corrupting their official medical history, or for other forms of fraud.

Individuals who receive notification about this breach should remain vigilant. It is generally recommended to review explanation of benefits statements and medical records for any unauthorized services or discrepancies. Additionally, monitoring financial accounts and credit reports for suspicious activity, and considering placing a credit freeze or fraud alert, are widely recommended protective steps. Regularly updating passwords for online accounts is also a wise precaution.

Commonly recommended next steps

  • Freeze your credit

    Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.

  • Check for medical identity theft

    Review the Explanation of Benefits statements from your health insurer for services or claims you never received, which can signal misuse of your medical identity.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Look up another company

Other breaches reported in Indiana

DataBreachSearch.com reports what was filed with state regulators. It is not legal advice, is not a law firm, and is not affiliated with any government agency or with Graham County Hospital.