Three Indiana organizations selected from the Attorney General’s public breach ledger for the first end-to-end demo runs. Everything here is organization-level public record.
Internal · Kelsie HartThe ledger behind these cases
Indiana law requires an organization that loses Hoosiers’ personal data to notify the Attorney General, who publishes the filings year by year. A notice is not a person — one person caught in four filings is four notices.
Selected cases
Roughly 100 affected Hoosiers each — large enough that the organization took it seriously enough to file, small enough that one agent can work the whole case properly.
The cleanest of the three and the most recent. Every affected person was a Hoosier, so there is no argument about whose problem this is, and six days between incident and filing suggests an organization that responded properly.
Domain carmelclaylibrary.org · verified 2026-08-30 · 425 E. Main St, Carmel IN · (317) 814-3900
Non-profit Area Agency on Aging serving nine northeast Indiana counties. The people affected are older adults — precisely the population targeted after an exposure. The strongest “why this matters” of the three.
Domain agingihs.org · verified 2026-08-30 · Fort Wayne IN · (260) 745-1200
Delaware County — the same county as the Meridian Health anchor finding, inside the East Central region. Oldest of the three, so this is the territory-relevance case rather than the urgent one.
Domain yorktownindiana.org · verified 2026-08-30 · 9312 W. Smith St, Yorktown IN · (765) 759-8521
The workflow