All Breaches
January 15, 2026 Verified Sensitive Record Healthcare

Family Health Centers of Southern Indiana 2026 Data Breach

The Family Health Centers of Southern Indiana 2026 data breach was a cybersecurity event affecting the organization’s network server, with an occurrence date of January 15, 2026 in official records. The Indiana Attorney General’s year-to-date breach report lists 7,304 affected people across the United States, including 7,037 Indiana residents.

The U.S. Department of Health and Human Services Office for Civil Rights also lists the same healthcare organization. HHS classifies the event as a Hacking/IT Incident, identifies the location as a Network Server, and reports 7,117 people. Because the sources do not explain the 187-person difference between the two official figures, the values are not added together; the 7,304 figure expressly labeled “Total Affected” in the Indiana report is used as the overall total.

How Was the Family Health Centers Breach Confirmed?

The primary evidence is the Indiana Attorney General’s 2026 data breach report. Its row gives the organization’s full name, records that notification was sent on June 18, 2026, identifies January 15, 2026 as the breach date, and lists 7,037 Indiana residents and 7,304 total affected people. The separate state and total columns establish that 7,304 is not an Indiana-only count.

The second official source is the HHS Office for Civil Rights breach portal. It identifies the organization as a Healthcare Provider, gives a June 18, 2026 submission date, classifies the event as a Hacking/IT Incident involving a Network Server, and lists 7,117 people. A ClaimDepot summary also reports the Indiana filing’s total of 7,304 and its 7,037 Indiana residents. The entity, timing, and nature of the event are therefore corroborated by two official records and one secondary source.

What Happened on January 15, 2026?

The facts established by the public regulatory records are limited: the breach occurred on January 15, 2026 and was reported as a hacking or information-technology incident involving a network server. The available sources do not say which vulnerability was used, how long unauthorized access lasted, whether files were removed, whether ransomware was deployed, or who was responsible.

For that reason, this entry does not label the event as ransomware, confirmed data theft, or the work of a particular threat group. “Hacking/IT Incident” and “Network Server” reproduce the HHS classification; they do not establish a more specific technical method. Although the notification date is about five months after the occurrence date, the public sources do not provide a discovery date or review-completion date, so those milestones are not estimated.

What Information May Have Been Affected?

Incidents published in the HHS portal are reports involving breaches of unsecured protected health information under HIPAA. The narrowest supportable data category for this event is therefore protected health information. However, the available Indiana report and HHS table row do not identify whether names, birth dates, Social Security numbers, diagnoses, treatment details, insurance information, financial accounts, patient numbers, or any other specific fields were present.

Data types disclosed in unrelated healthcare incidents should not be transferred to this case. An individual notification letter may identify the fields relevant to that recipient more precisely than the public summaries, so the letter should control. Presenting undisclosed fields as confirmed could exaggerate the risk and distract an affected person from the accounts and documents that actually need attention.

Why Do the Counts of 7,304 and 7,117 Differ?

The Indiana Attorney General report expressly labels 7,304 as the total affected population and 7,037 as the number affected in Indiana. Those values imply that at least 267 affected people were outside Indiana. The HHS portal lists 7,117 for the same organization and submission date. That HHS figure is 187 lower than Indiana’s total, but neither agency explains whether the difference reflects scope, timing, or another reporting rule.

The three figures should consequently be read for their stated purposes: 7,304 as the nationwide total, 7,037 as the Indiana resident count, and 7,117 as the number separately published in the HHS portal. The values 7,304 and 7,117 are not combined, and 7,117 is not presented as a newer total. The displayed affected-person count uses the official value expressly labeled as the overall total; the entry can be reviewed again if a regulator later amends its record.

What Is Known About the Organization and Notification?

On its official website, Family Health Centers of Southern Indiana says it provides community health services in Jeffersonville, New Albany, Corydon, and Clarksville and operates a mobile dental unit. The organization describes its mission as delivering primary healthcare to underserved communities, including people with low income and those who are underinsured or uninsured. This information is used only to confirm the identity and context of the affected organization.

The accessible sources do not provide a detailed organization notice, an offer of free credit monitoring, an attribution statement, or a declaration about whether misuse has been detected. The absence of those details does not establish that no assistance was offered or that misuse occurred; it defines the limit of the public evidence. Recipients should rely on the current instructions in their notification letters for support terms and contact information.

What Should Affected People Do?

A recipient should first review the notification letter for the data fields that apply to them and for any deadline attached to offered assistance. Patient portals, health-insurance explanation-of-benefits statements, and medical bills can be checked for an unfamiliar service, provider, prescription, or contact-detail change. If an unknown health record appears, contact the provider or insurer through an independently verified official channel rather than a link in a message.

Do not provide a password, one-time code, payment detail, or additional health information in an unexpected email or call using the Family Health Centers, insurer, or support-provider name. If the individual letter expressly says a Social Security number or financial information was involved, review credit reports and consider a free fraud alert or credit freeze. If the letter does not list such a field, the public records alone do not support assuming it was affected.

7.3 Thousand
Affected Accounts
1
Data Types
Low
Severity
Yes
Verification

Exposed Data Types

1
Protected health information

Additional Information

Added DateJuly 27, 2026
Breach DateJanuary 15, 2026
Domainfhcenters.org
SourceIndiana Attorney General and HHS records confirming a healthcare network-server hacking incident
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information