Indianapolis OB-GYN Caitlin Bernard provided a legal abortion to a 10-year-old rape victim from Ohio. After the story broke, her name, employer, and personal details circulated nationally; she received death threats; Indiana's attorney general opened an investigation.
What happened
On July 1, 2022, the Indianapolis Star reported that an Indianapolis OB-GYN had provided a legal abortion to a 10-year-old rape victim who had traveled from Ohio. The patient was not named. The physician was Dr. Caitlin Bernard.
Within days her name was everywhere. National outlets republished it. Social-media accounts pulled her employer, Indiana University Health, along with her photo and professional background. Bernard received death threats at home and at work. Indiana Attorney General Todd Rokita publicly questioned whether she had violated state reporting requirements and opened an investigation.
In May 2023 the Indiana Medical Licensing Board reprimanded Bernard for a privacy-disclosure violation tied to speaking about the case. The care she provided was never found unlawful, and the board cleared her on the count alleging she failed to report the abuse.
How it started
Bernard was not hacked, and she did not post her own address. She did her job, the patient's story reached the news, and her name surfaced through routine reporting. Once a name is public, the home address behind it is rarely far. People-search brokers compile profiles from voter rolls, property records, and other public filings, then sell the home address behind a name to anyone with a credit card. That pipeline runs on public data, not a leak, and the pages were built long before her name entered the news cycle.
Why this case matters
Bernard did legal work, and the doxxing followed as a reaction to it. The attorney general's investigation raised the profile further, shifting the pressure from anonymous threats to a formal state proceeding.
For physicians providing reproductive care, gender-affirming care, or any treatment that draws political attention, the sequence is recognizable: the story breaks, the name surfaces, threats arrive at home and at work, and sometimes a regulator gets involved. Through all of it, the home address sits on broker pages that were built before any of it started.
What separates this from a one-on-one stalking case is the trigger. Here it was public attention rather than a personal relationship. The lookup that turns a name into a home address works the same way in either situation.
What this means for you
If you provide care that draws political or media attention, treat the Bernard sequence as the working model. Your name and your employer are likely already discoverable, and your home address is one search away unless you have already had it removed.
The federal Driver's Privacy Protection Act, or DPPA, limits what state motor-vehicle agencies can hand out about you. It does not reach a broker page that already holds your address from voter rolls or property records. Indiana has no Daniel's Law equivalent — the targeted statute some states give police, judges, and other at-risk workers to compel brokers to remove their home addresses. Its 2026 Consumer Data Protection Act does let residents ask data brokers that meet its size thresholds to stop selling their data and delete it, but that is general consumer law enforced by the attorney general, with no targeted protection for physicians and nothing that keeps a removed listing from reposting. The practical fix is standing removal across the commercial sites that resell home addresses by name, kept current because listings tend to reappear.
If you have been named, see what physicians face and the doxxing recovery checklist.
The medical board ruling
On May 25, 2023, after a hearing that ran about 15 hours, the Indiana Medical Licensing Board found in split votes that Bernard violated state and federal patient-privacy law on three counts by speaking publicly about the case, even though she never named the patient. It fined her $1,000 per count, $3,000 in total, and issued a letter of reprimand. The board cleared her on the separate counts alleging she failed to report child abuse and was unfit to practice, and it did not restrict her license. Neither side appealed, and the case closed in August 2023. Coverage from the Indianapolis Star laid out the votes and the underlying complaint.
The ruling matters here because the same public statements that drew anonymous death threats also produced a formal, on-the-record sanction. The doxxing, the harassment, and the regulatory action all traced back to one act: speaking about a case she had handled lawfully.
The Rokita disciplinary case
Rokita's public comments drew consequences of their own. In a 2022 interview he described Bernard as "an abortion activist acting as a doctor — with a history of failing to report," before his investigation had concluded. The Indiana Supreme Court Disciplinary Commission brought misconduct charges, and in November 2023 the court publicly reprimanded Rokita, finding he violated two of the Rules of Professional Conduct that limit what a lawyer may say about a pending investigation. NPR and the Indiana Citizen reported the charges and the reprimand. A later set of charges over Rokita's public response to the reprimand was dismissed as moot in October 2025.
None of these proceedings pulled Bernard's information off the broker pages or undid the threats she received. They are noted here because the official who escalated against her was himself disciplined for how he did it. The underlying exposure was never addressed by any of these proceedings, and removing it is left to whatever the affected people arrange on their own.
What reduces this risk
Bernard's name and employer were already public. Doxxing a named person needs no hack: people-search brokers compile home addresses from voter rolls, property records, and other public filings, then sell them by name to anyone with a credit card. The same lookup runs against any nurse, physician, or hospital worker whose name reaches a news cycle. Indiana's 2026 consumer-privacy law lets residents ask covered brokers to stop selling their data and delete it, but nothing stops a removed listing from reappearing, so the practical fix is standing removal across the commercial sites that resell home addresses by name. Frontline Privacy scans the major broker sites, files opt-outs, and re-files when a listing comes back.
Public sources
- Patients head to Indiana for abortion services as other states restrict care — Indianapolis Star, 2022-07-01
- Indiana abortion doctor violated privacy law, medical board rules — Indianapolis Star, 2023-05-25
- Indiana Supreme Court reprimands Rokita over abortion doctor remarks — NPR, 2023-11-03
- Disciplinary charges: AG Rokita charged with three counts of attorney misconduct by Indiana judicial panel — Indiana Citizen, 2023-09-18