Call-on-Doc Telehealth Reports Texas Data Breach Impacting Patient Records
Call-on-Doc, a telehealth services provider, reported a data breach to the Texas Attorney General on September 21, 2026, stemming from an incident on December 22, 2025. The exposed information includes sensitive patient details such as Full Name, Social Security Number, and comprehensive medical records. This incident creates risks of identity theft and potential medical fraud for affected individuals.
- State
- Texas
- Breach date
- December 22, 2025
- Reported
- September 21, 2026
What may have been exposed
- Full Name
- Date of Birth
- Social Security Number
- Medical Record Number
- Health Insurance ID Number
- Diagnosis and Treatment Information
- Prescription Information
- Provider and Treatment Dates
- Billing and Financial Information
Call-on-Doc, a telehealth services provider, filed a data breach notification with the Texas Attorney General on September 21, 2026. This filing, available in public records, details a security incident that occurred on or around December 22, 2025. The company's investigation into the specifics of how the breach occurred is currently ongoing.
The compromised information includes a wide range of sensitive personal and health data. Affected individuals may have had their Full Name, Date of Birth, Social Security Number, Medical Record Number, Health Insurance ID Number, Diagnosis and Treatment Information, Prescription Information, Provider and Treatment Dates, and Billing and Financial Information exposed. This collection of data represents a comprehensive snapshot of an individual's identity and medical history.
Because Call-on-Doc facilitates online medical consultations and prescription services, it routinely collects and stores extensive personal and health records. The digital nature of its operations means it relies heavily on electronic storage for this sensitive data. The exposure of such detailed information presents substantial risks, as it could be exploited for various forms of fraud.
Individuals whose data was compromised face potential threats such as medical identity theft, where their health insurance or medical records could be used to obtain unauthorized care or services. The combination of personal identifiers and health information also increases the risk of financial identity theft and targeted phishing attacks. These sophisticated scams often leverage specific personal details to appear more credible to victims.
Those who receive a data breach notification from Call-on-Doc should take immediate and proactive steps to protect their personal information. It is recommended to carefully review all financial account statements and health insurance explanations of benefits (EOBs) for any suspicious or unauthorized activity. Additionally, individuals may consider placing a fraud alert or security freeze on their credit reports with the major credit bureaus to help prevent new fraudulent accounts from being opened in their name.
What to do if you were affected
Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.
Freeze your credit
Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.
Watch your financial accounts
Review bank and card statements for unfamiliar activity and turn on transaction alerts. Report anything you don't recognize to your bank right away.
Check for medical identity theft
Review the Explanation of Benefits statements from your health insurer for services or claims you never received, which can signal misuse of your medical identity.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Source: Texas Attorney General filing
Related data breach cases
- Aprio Advisory Group, LLC
- Seyfarth Shaw LLP
- Doctor's Choice Home Care
- Affordable Mortgage Advisors
- Opportune LLP
- IDScan.net
- The City of Jacksonville, TX
- Boston Capital Holdings LP
- Three Oaks Hospice, Inc.
- Three Oaks Hospice of West Houston
- Three Oaks Hospice of San Antonio
- Three Oaks Hospice of North East Texas
- Three Oaks Hospice of Fort Worth
- Mitchell County Hospital District