NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Call-on-Doc Notifies Patients About December 2025 Hacking Incident

The telemedicine platform operator Call-on-Doc has notified patients about a December 2025 cyberattack and data breach. Data breaches have also been announced by Provident Behavioral Health, Vernon & Waldrep OB-Gyn Associates, and Partnership HealthPlan of California.

Call-on-Doc

Call-on-Doc, Inc., a Dallas, Texas-based online telemedicine platform provider, started issuing notification letters on September 18, 2026, about a cybersecurity incident that occurred in December 2025. Suspicious activity was identified within its computer systems on December 28, 2025. The forensic investigation determined that an unauthorized third party had access to its network from December 22, 2025, to January 3, 2026. The affected parts of its network were reviewed, and on August 19, 2026, it was confirmed that protected health information was compromised in the incident.

The types of data involved vary from individual to individual and may include names, email addresses, physical addresses, phone numbers, diagnoses, medical information, and visit types. Call-on-Doc said it has not detected any instances of fraud related to the incident. The notifications do not provide any further information on the nature of the attack; however, a threat actor claimed responsibility for the attack and attempted to sell the stolen data in January 2026. The threat actor claimed to have stolen personal and medical information of more than 1.1 million individuals, although that claim has not been verified. Call-on-Doc has not yet publicly disclosed how many individuals were affected by the incident, and the incident is not currently shown on the HHS’ Office for Civil Rights website.

Provident Behavioral Health

Provident Behavioral Health, a St. Louis, Missouri-based provider of counselling and psychiatric services, has disclosed a data breach involving the protected health information of 25,086 individuals.  Unusual activity was identified within its computer systems on April 3, 2026. The impacted systems were isolated, and a third-party cybersecurity firm was engaged to conduct a forensic investigation and remediate the issue.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The forensic investigation found evidence that files stored on the impacted systems were acquired by an unauthorized third party. The data review has recently been completed and confirmed that data compromised in the incident included names, contact information, demographic information, birth dates, Social Security numbers, driver’s license numbers, medical information, and health insurance information. All administrative credentials have been changed, and security measures have been enhanced to reduce the risk of similar incidents in the future. The affected individuals were notified on September 4, 2026.

Vernon & Waldrep OB-Gyn Associates

Vernon & Waldrep OB-Gyn Associates, a Dallas, Texas-based women’s healthcare practice, has notified 16,876 patients about a network intrusion that exposed patients’ personal and protected health information. The intrusion was identified on July 28, 2026, and immediate action was taken to secure its network and prevent further unauthorized access.

The forensic investigation determined that a threat actor accessed systems containing patient data such as names, addresses, phone numbers, dates of birth, treatment and diagnosis information, claims information, medical provider names, lab test results, and health insurance information. Vernon & Waldrep said it has not identified any misuse of the affected data. While not mentioned in the notification letters, a ransomware group called Global Secret Group claimed responsibility for the attack on August 1, 2026, alleging that 274 GB of data was stolen, including patient records.

Partnership HealthPlan of California

Partnership HealthPlan of California, a Fairfield, California-based managed care provider, has notified 1,526 individuals about a breach of their protected health information. According to the notification letters, a privacy incident was identified on July 7, 2026, involving Primary Care Physician (PCP) Selection Forms and Welcome Packets. The investigation determined that certain mailings were sent between May 13, 2026, and July 8, 2026, that contained information of unrelated members. Mailings included another individual’s name, date of birth, and membership identification number. Partnership HealthPlan of California said it has reviewed and strengthened its privacy and security safeguards, provided additional workforce training, and taken other steps to prevent similar incidents in the future.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist