240 Health Tech Reports Data Breach in Indiana
Indiana-based health software provider 240 formally reported a data breach in February 2026, confirming the exposure of highly sensitive personal and health information. This incident includes data like Social Security Numbers and detailed medical records, posing significant risks for identity theft and medical fraud for affected individuals.
- State
- Indiana
- Breach date
- June 17, 2025
- Reported
- February 18, 2026
What may have been exposed
- Full Name
- Date of Birth
- Social Security Number
- Medical Record Number
- Health Insurance ID Number
- Diagnosis and Treatment Information
- Prescription Information
- Provider and Treatment Dates
240, a specialized provider of software solutions and patient management systems in the digital health sector, filed an official data breach report with the Indiana Attorney General in February 2026. This report followed a cybersecurity incident that occurred on June 17, 2025, affecting sensitive information stored within their systems.
The breach involved a range of personal and protected health information. The specific data types reported as exposed include Full Name, Date of Birth, Social Security Number, Medical Record Number, Health Insurance ID Number, Diagnosis and Treatment Information, Prescription Information, and Provider and Treatment Dates. The extensive nature of this exposed data can lead to serious risks for those affected.
Individuals who received a notification regarding this incident should take immediate steps to protect themselves. It is advisable to review all Explanation of Benefits (EOB) statements from health insurers carefully for any unauthorized activity. Monitoring financial statements and credit reports for suspicious transactions or new accounts opened in one's name is also recommended. Consider placing a fraud alert with credit bureaus as a preventative measure.
This information is derived from public filings made by 240 with regulatory authorities in Indiana. The filing serves as official documentation of the data compromise and provides details regarding the types of information that were potentially accessed by unauthorized parties.
What to do if you were affected
Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.
Freeze your credit
Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.
Check for medical identity theft
Review the Explanation of Benefits statements from your health insurer for services or claims you never received, which can signal misuse of your medical identity.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Source: Indiana Attorney General filing
Related data breach cases
- Teamsters Local 17
- Bank
- American Motorcyclist Association
- Deer Management Co. LLC dba Bessemer Venture Partners
- MEBS Global Reach
- McKenzie Creative Brands
- Midvale Indemnity and American Family Connect Insurance Company
- Nishiyamato Academy
- 9World Acceptance Corporation
- Chicago Psychoanalytic Institute
- Poppins Payroll Company
- Baltimore Medical System Inc
- Pavillon International Inc
- 7The Association of the Bar of the City of New York