Indiana University Health Inc

09/29/2026 | Press release | Distributed by Public on 09/29/2026 21:12

IU Health reports vendor security incident in Southern Indiana

INDIANAPOLIS -- Indiana University Health Affiliated Covered Entity (IU Health) announced today that its vendor detected suspicious activity prompting the vendor to initiate their incident response protocols.

On August 4, 2026, IU Health learned that AME Group ("AME"), an IU Health IT vendor, may have been susceptible to a previously unknown software vulnerability associated with the information technology services AME was providing to an isolated IU Health legacy system. There is no evidence that IU Health's network or core systems were impacted. Upon notice, IU Health took immediate steps to verify the security of its systems, which remain unaffected. Additionally, IU Health undertook an independent review of AME's external vendor managed system to help determine what, if any, information may have been impacted. This review resulted in a determination of unauthorized access to limited imaging center information related to certain Southern Indiana patients' radiology files stored on the legacy system. There was no access to the IU Health electronic medical record system and patient care was not impacted.

The information involved varied by individual, but may have included name, date of birth, health plan member identification number, and other limited treatment information associated with the imaging center.

IU Health began notifying affected individuals on September 29, 2026, to make them aware of the situation and is providing dedicated call center support to answer any questions. We are committed to protecting personal information, and IU Health continues to implement security measures to prevent these activities from occurring in the future.

If you have any questions, please call toll-free at 888.752.8187, 9:00 a.m. to 9:00 p.m. Eastern Time, Monday-Friday (except major U.S. holidays).

Indiana University Health Inc published this content on September 29, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on September 30, 2026 at 03:12 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]