Protect⁠Indiana.org · Personal Service Task Force

Case console

Three Indiana organizations selected from the Attorney General’s public breach ledger for the first end-to-end demo runs. Everything here is organization-level public record.

Internal · Kelsie Hart

The ledger behind these cases

8,989 filed notices. Three chosen.

Indiana law requires an organization that loses Hoosiers’ personal data to notify the Attorney General, who publishes the filings year by year. A notice is not a person — one person caught in four filings is four notices.

8,989notices filed, 2014–2026
10,088,526Indiana-resident notices
784filings in the 60–220 band
2019missing entirely — recorded as a gap, never estimated

Selected cases

Small enough to finish. Real enough to prove.

Roughly 100 affected Hoosiers each — large enough that the organization took it seriously enough to file, small enough that one agent can work the whole case properly.

Primary case

Carmel Clay Public Library

108Hoosiers notified
100%of victims were Hoosiers
2026-02-03incident date
2026-02-09filed with the AG

The cleanest of the three and the most recent. Every affected person was a Hoosier, so there is no argument about whose problem this is, and six days between incident and filing suggests an organization that responded properly.

Domain carmelclaylibrary.org · verified 2026-08-30 · 425 E. Main St, Carmel IN · (317) 814-3900

Mission case

Aging & In-Home Services of Northeast Indiana

112Hoosiers notified
98.25%of victims were Hoosiers
2025-03-03incident date
2025-08-08filed with the AG

Non-profit Area Agency on Aging serving nine northeast Indiana counties. The people affected are older adults — precisely the population targeted after an exposure. The strongest “why this matters” of the three.

Domain agingihs.org · verified 2026-08-30 · Fort Wayne IN · (260) 745-1200

Territory case

Town of Yorktown

96Hoosiers notified
93.20%of victims were Hoosiers
2014-05-01incident date, per filing
2021-01-26filed with the AG

Delaware County — the same county as the Meridian Health anchor finding, inside the East Central region. Oldest of the three, so this is the territory-relevance case rather than the urgent one.

Domain yorktownindiana.org · verified 2026-08-30 · 9312 W. Smith St, Yorktown IN · (765) 759-8521

Runner-up worth a look: School-Based Behavior Consultation LLC filed twice in 2026 (163 and 142 Hoosiers). A repeat exposure at one small organization is a sharper story if we would rather demonstrate a pattern than an incident. Its domain is not yet verified — do not approach until it is.

The workflow

Where it runs, and exactly where it stops

  1. 1Event researchWhat the filing says: dates, counts, whether the organization published its own notice.No gate
  2. 2Organization profileSize, sector, who it serves, verified domain, named contact route.No gate
  3. 3Case fileWhat the exposure means for their people and what a domain check would tell them.No gate
  4. 4Domain checkReturns addresses only after the organization verifies it controls the domain. Theirs to unlock, not ours to run.Org must authorise
  5. 5Any outbound contactUnder the standing outbound freeze. Requires Adam’s explicit go, per case.Adam’s call
Never, at any step: no stolen data is bought, downloaded, or held; no passwords or payment details are retrieved; no individual’s personal information is sourced from a breach corpus. The organization notifies its own people — it has the relationship and the duty.

Read the full case brief →