# WindRose notifies 33,158 people after vendor-tool breach

_Published Monday, October 5, 2026 at 2:18 PM EDT · Security · Latest · Tier 2 — Notable_

![WindRose notifies 33,158 people after vendor-tool breach — Primary](https://www.hipaajournal.com/wp-content/uploads/2026/06/healthcare-security-breach-V4.jpg)

WindRose Health Network has started notifying 33,158 individuals after an intruder exploited a previously undisclosed vulnerability in a vendor's remote access tool, HIPAA Journal reported. The Indiana health center network's investigation found unauthorized access between August 3 and August 4, 2026.

Patient names, patient ID numbers, health insurance information, dates of service and provider names were potentially accessed or copied from files on the affected network. The remote access tool could not access patients' medical records.

The vendor informed WindRose of the vulnerability on August 4. WindRose secured its environment, engaged cybersecurity experts and advised affected patients to watch for identity theft and fraud.

## Sources

- [HIPAA Journal](https://www.hipaajournal.com/windrose-health-network-data-breach/)

---
Canonical: https://techandbusiness.org/newswire/MHNZp-DqlwXJBQpxw3GGr3
Published: 2026-10-05T18:18:47.004Z
Story chronology: 2026-10-05T16:49:17.000Z
Retrieved: 2026-10-05T19:50:49.004Z
Publisher: Tech & Business (techandbusiness.org)
