Franciscan Alliance Reports Data Breach Affecting Sensitive Records
Franciscan Alliance, operating its Working Well division in Indiana, reported a data security incident on February 20, 2026, which occurred on December 18, 2025. The breach exposed a wide range of sensitive health and employment-related information, requiring affected individuals to take protective measures.
- State
- Indiana
- Breach date
- December 18, 2025
- Reported
- February 20, 2026
What may have been exposed
- Full Name
- Date of Birth
- Social Security Number
- Medical Record Number
- Health Insurance ID Number
- Diagnosis and Treatment Information
- Workers' Compensation Records
- Employer and Employment Details
Franciscan Alliance Inc., through its Franciscan Working Well division in Indiana, formally reported a data security incident to regulators on February 20, 2026. The organization indicated that the breach itself took place on December 18, 2025.
Franciscan Working Well serves as a specialized healthcare and occupational health provider, partnering with employers to offer various employee health services. This includes services such as pre-employment physicals, drug screenings, workers' compensation management, and immunizations, necessitating the management of extensive personal and health records.
The reported breach compromised sensitive data elements, according to official filings. The categories of information exposed include Full Name, Date of Birth, Social Security Number, Medical Record Number, Health Insurance ID Number, Diagnosis and Treatment Information, Workers' Compensation Records, and Employer and Employment Details.
The exposure of this combination of personal and health data creates potential risks for affected individuals. Such information can be targeted for various forms of identity theft, medical fraud, or other misuse.
Individuals who believe they may be affected by this incident should consider monitoring their financial and healthcare statements for any suspicious activity. Placing a fraud alert with major credit bureaus and regularly reviewing credit reports can help detect and prevent potential misuse of exposed personal information.
What to do if you were affected
Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.
Freeze your credit
Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.
Guard against tax fraud
File your tax return as early as possible and consider requesting an IRS Identity Protection PIN so no one can file a fraudulent return in your name.
Check for medical identity theft
Review the Explanation of Benefits statements from your health insurer for services or claims you never received, which can signal misuse of your medical identity.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Source: Indiana Attorney General filing
Related data breach cases
- Teamsters Local 17
- Bank
- 9World Acceptance Corporation
- McKenzie Creative Brands
- MEBS Global Reach
- Midvale Indemnity and American Family Connect Insurance Company
- American Motorcyclist Association
- Nishiyamato Academy
- Deer Management Co. LLC dba Bessemer Venture Partners
- The Association of the Bar of the City of New York
- Poppins Payroll Company
- Baltimore Medical System Inc
- Chicago Psychoanalytic Institute
- 7The Association of the Bar of the City of New York