DataBreachCaseFile.com
MonitoringIndiana AG filing · September 4, 2026

Alvita Care Holdings Reports 2026 Data Incident in Indiana

Alvita Care Holdings disclosed a data security incident on September 4, 2026, impacting sensitive personal and medical information. This event, which occurred on March 25, 2026, exposes individuals to risks including medical identity theft and financial fraud, necessitating vigilance over their records.

State
Indiana
Breach date
March 25, 2026
Reported
September 4, 2026

What may have been exposed

  • Full Name
  • Date of Birth
  • Social Security Number
  • Medical Record Number
  • Health Insurance ID Number
  • Diagnosis and Treatment Information
  • Home Address
  • Phone Number

Alvita Care Holdings specializes in home care and specialized healthcare services, assisting vulnerable populations with professional nursing and daily living support. In its operations, the company routinely collects and maintains a wide range of sensitive personal and medical data for its clients and employees, including Full Name, Date of Birth, Social Security Number, Medical Record Number, Health Insurance ID Number, Diagnosis and Treatment Information, Home Address, and Phone Number.

On September 4, 2026, Alvita Care Holdings reported a data security incident to the Indiana Attorney General. The company indicated that this incident, initially identified on March 25, 2026, involved the exposure of client and employee information. The investigation into the scope and impact of this breach is currently under monitoring.

The compromised data categories specifically include Full Name, Date of Birth, Social Security Number, Medical Record Number, Health Insurance ID Number, Diagnosis and Treatment Information, Home Address, and Phone Number. The exposure of such detailed personal and health-related information can have significant implications for affected individuals.

When data like Social Security Numbers and medical records are exposed, individuals face a heightened risk of medical identity theft. This can involve unauthorized parties using a victim's identity to obtain healthcare services, prescription drugs, or medical equipment, potentially complicating their medical history. Furthermore, the combination of personal identifiers and detailed health information can facilitate financial fraud, unauthorized credit applications, and targeted phishing scams.

Individuals who receive notification of this breach should take proactive steps to safeguard their identity and finances. This includes diligently reviewing financial statements, credit reports from all three major bureaus, and Explanation of Benefits (EOB) statements from their health insurer for any unauthorized activity. Placing a fraud alert or a credit freeze on their credit files with nationwide credit reporting agencies is also a recommended precaution.

This information is based on public filings submitted to regulatory authorities, detailing the facts of the reported data security incident.

What to do if you were affected

Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.

  • Freeze your credit

    Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.

  • Check for medical identity theft

    Review the Explanation of Benefits statements from your health insurer for services or claims you never received, which can signal misuse of your medical identity.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Source: Indiana Attorney General filing

Related data breach cases