Indiana University Health has begun notifying some Southern Indiana patients that limited information from their radiology files was accessed without authorization through a technology vendor, the health system said Sept. 29.
The information varied by person but may have included a patient's name, date of birth, health plan member ID number, and other limited treatment information tied to an imaging center, according to IU Health's announcement. IU Health did not list Social Security numbers or financial account information among the exposed data.
For affected households, the most practical concern is the insurance member ID. Someone with that number and a name could try to bill an insurer for care the patient never received. Checking insurance statements over the coming months is a simple way to catch that early.
A Vendor's Legacy System Was the Entry Point
IU Health said it learned on Aug. 4, 2026, that its IT vendor, AME Group, may have been susceptible to a "previously unknown software vulnerability" tied to services AME provided for an older, isolated IU Health system. An independent review found unauthorized access to imaging center information stored on that legacy system.
"There is no evidence that IU Health's network or core systems were impacted," the health system said. It added that "there was no access to the IU Health electronic medical record system and patient care was not impacted."
Becker's Hospital Review reported the same details. IU Health has not said how many patients were affected, which imaging centers were involved, or when the access occurred. Those gaps leave many Southern Indiana families unsure whether they are included, so the notice itself is the clearest confirmation. IU Health has not said whether it will offer credit monitoring.
Patients with questions can call IU Health's dedicated line at 888-752-8187, 9 a.m. to 9 p.m. Eastern time, Monday through Friday, except major U.S. holidays.
The Insurance Member ID Is the Key Risk
Medical identity theft happens when someone uses another person's information to get care, prescriptions, or equipment, or to submit insurance claims. The Federal Trade Commission lists warning signs, including bills for care you did not receive, calls from debt collectors about unfamiliar medical debts, and notices that you have reached a benefit limit.
The best early warning is the Explanation of Benefits, or EOB, that insurers send after each claim. The FTC notes that an EOB "tells you the doctor you visited, the date of your visit, the services the doctor provided, the cost of those services, how much your health insurance covered, and how much you'll have to pay."
Patients can sign in to their insurer's website or app to review recent claims rather than waiting for paper statements. Any visit, test, or prescription that looks unfamiliar is worth a call to the insurer's fraud line. People on Medicare can check their Medicare Summary Notices the same way.
Some households will find this harder than others. Older adults and people with chronic conditions often receive many statements each month, which makes one false claim easy to miss. Adult children who help manage a parent's care may want to review those statements together. Misuse can also surface months after a breach, so checking statements through at least the next year is a sensible habit.
Practical Steps for Affected Patients
Patients who receive a notice should keep it, since it may be needed later to dispute a claim. They can call their health plan, explain that their member ID may have been exposed, and ask whether a new ID number can be issued.
Because Social Security numbers were not listed among the exposed data, a credit freeze may not be necessary for everyone. Still, a credit freeze is free and must be placed separately with Equifax, Experian, and TransUnion. Patients can also check their free credit reports for medical collections they do not recognize.
If misuse is found, the FTC's IdentityTheft.gov site helps people report it and build a recovery plan. Patients should also ask providers for copies of their records to correct any false entries, because errors in a medical file can affect future care.
Patients should be cautious about calls, texts, or emails that mention the incident and ask for payment or personal details. Scammers often follow publicized breaches. When in doubt, hang up and call IU Health or your insurer using a number from an official statement, not one provided by the caller.
Patients who did not receive a notice have no specific reason to act, but routinely reviewing EOBs is a good habit for anyone with health insurance.
Key Questions Answered
What happened at IU Health? A vendor, AME Group, may have been susceptible to a software flaw, and an unauthorized party accessed limited radiology information from an older IU Health system.
What information was involved? It varied, but may have included name, date of birth, health plan member ID, and limited imaging treatment details.
Were medical records or Social Security numbers exposed? IU Health said its electronic medical record system was not accessed, and Social Security numbers were not listed among the exposed data.
How many patients were affected? IU Health has not disclosed a number.
What should affected patients do? Review insurance statements, contact their health plan, and report unfamiliar claims.
Who can patients call? IU Health's line is 888-752-8187, weekdays from 9 a.m. to 9 p.m. Eastern time.
Should affected patients freeze their credit? It is optional, since Social Security numbers were not listed. A freeze is free, though, and can be placed with each of the three major credit bureaus for added peace of mind.
Published by Medicaldaily.com