Campbell Clinic, a Tennessee orthopaedic practice, began notifying patients in September 2026 that hackers accessed personal information including Social Security numbers. The cause and number of people affected have not been made public. If you received a notice, place a fraud alert or credit freeze with all three credit bureaus right away and monitor your financial and insurance statements closely.
| Company | Campbell Clinic |
|---|---|
| Industry | Healthcare |
| Data Types Exposed | Social Security Numbers, Other Personal Information Not Specifically Itemized |
| People Affected | Not Publicly Disclosed |
| Attack Method | Unspecified/Unauthorized Access |
| Regulators Notified | Not Publicly Disclosed |
Were you affected by this breach?
You may be owed compensation.
Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.
Check if you qualify — free reviewWhat Happened in the Campbell Clinic Data Breach?
Campbell Clinic, an orthopaedic and sports medicine practice based in Germantown, Tennessee, has begun telling patients that someone accessed their personal information without permission. The Campbell Clinic data breach came to light when the practice sent notification letters starting in September 2026. Those letters confirm that Social Security numbers were among the data involved.
At this point, the clinic has not shared many specifics. It has not explained how an intruder got into its systems. It also has not said whether the event involved ransomware, a phishing scheme, or some other method. As a result, outside observers can only rely on what the notification letters themselves describe.
The exact timeline also remains unclear. Campbell Clinic has not disclosed when it first discovered the intrusion, nor how long unauthorized access may have continued before it was stopped. Because the discovery date has not been publicly disclosed, patients cannot yet judge whether the notice arrived within the window healthcare privacy law typically expects. This gap is one reason attorneys reviewing the matter are paying close attention to the timeline.
Federal rules under HIPAA generally require healthcare providers to notify patients without unreasonable delay, and no later than 60 days after discovering a breach. Since Campbell Clinic has not revealed its discovery date, it is not yet possible to confirm whether that deadline was met. This remains an open question as more facts emerge.
Who was affected?
Patients who received care at Campbell Clinic appear to be the primary group affected by this breach. The practice offers orthopaedic treatment, sports medicine, joint replacement, and physical therapy to residents across the greater Memphis area. Because it serves such a wide range of patients, the breach could touch people of many ages, including families who sought treatment for sports injuries or joint conditions.
The exact number of people affected has not been publicly disclosed. Campbell Clinic has not released a total count in its notifications or public statements. Until that number becomes available, affected patients should assume the notification letter they received personally applies to their own records.
Because the clinic provides specialty orthopaedic services, its patient files likely include a broad mix of identity, insurance, and treatment information. This means the population affected could include both long-term patients and those who visited for a single procedure. Anyone treated by the practice, even briefly, should take the notice seriously.
What Information Was Potentially Exposed?
The clearest confirmed detail in this incident is that Social Security numbers were accessed. Campbell Clinic has not provided a full, itemized list of every data category involved. Because the organization is a medical provider, other related information may also have been exposed for at least some patients.
- Social Security numbers
- Other personal information not specifically itemized in public notices
A stolen Social Security number is especially dangerous because, unlike a password, it cannot simply be changed. Criminals can use it to open new credit cards, apply for loans, or file fraudulent tax returns in a victim’s name. Because medical files often combine identity data with insurance details, this breach could also create a path toward medical identity fraud, even though no health information has been specifically named in public notices.
This type of fraud often takes time to surface. A stolen number might sit unused for months before someone applies for credit or files a tax return using it. Victims frequently find out only when they are denied a loan or when their legitimate tax return gets rejected because a fraudulent one was filed first. This is why early monitoring matters more than waiting for signs of misuse to appear.
What is the company doing?
Campbell Clinic has begun sending written notification letters to patients whose information was involved. These letters started going out in September 2026 and represent the clinic’s confirmed response so far. The notices identify Social Security numbers as compromised and direct patients toward next steps.
Beyond sending these notices, Campbell Clinic has not publicly described additional remediation steps, such as system upgrades or expanded security measures. It also has not detailed whether credit monitoring or identity protection services are being offered to affected patients. Anyone who receives a letter should read it in full, since it may contain specific offers or instructions not reflected in general public reporting.
Patients who have not yet received a letter, but who have questions about whether their records were involved, can contact the clinic directly. Because many details remain undisclosed, the safest approach is to treat the letter itself as the most accurate and current source of information about your specific situation.
What Should Affected Individuals Do?
Place a Fraud Alert or Credit Freeze
Because Social Security numbers were exposed, placing a fraud alert or credit freeze is one of the most effective protective steps available. A freeze blocks new creditors from accessing your credit file, which makes it much harder for criminals to open accounts in your name. This service is free at all three major credit bureaus.
To set one up, contact Equifax, Experian, and TransUnion individually, since a freeze placed with one bureau does not automatically apply to the others. A fraud alert offers a lighter layer of protection and requires lenders to verify your identity before extending credit. Either option is a reasonable first move while more facts about this breach become available.
Monitor Your Credit Reports
Regularly reviewing your credit reports helps you catch suspicious activity early. You can request a free report from each of the three major bureaus through annualcreditreport.com. Because fraud from stolen Social Security numbers can surface long after a breach, checking periodically over the coming months is wise.
Look specifically for accounts you do not recognize, unexpected credit inquiries, or changes to your personal details. If you spot anything unusual, dispute it with the bureau right away. Keeping a record of your checks can also help if you later need to document harm for a legal claim.
Watch for Signs of Medical or Insurance Fraud
Because Campbell Clinic is a medical provider, patients should also review their insurance explanation-of-benefits statements. These documents list services billed to your insurance and can reveal whether someone used your identity to obtain care you never received. Catching this early can prevent larger billing disputes down the road.
If you notice unfamiliar charges or services on these statements, contact your insurer immediately. In addition, consider asking Campbell Clinic directly whether treatment or diagnosis information was included in your specific exposure. Comparing the clinic’s answer to your own letter can help clarify your personal risk level.
Stay Alert for Phishing Attempts
After a healthcare data breach, scammers sometimes use leaked details to craft convincing phishing emails, texts, or phone calls. These messages may reference the clinic by name or mention your medical history to appear legitimate. Because of this, treat any unexpected contact about your care or billing with caution.
Never click links or share personal details in response to unsolicited messages. Instead, contact Campbell Clinic directly using a verified phone number if you want to confirm a communication is real. This simple habit can prevent a second wave of harm following the original breach.
Consider Requesting an IRS Identity Protection PIN
Since Social Security numbers were involved, tax fraud is a realistic concern. An IRS Identity Protection PIN adds a layer of security that makes it harder for criminals to file a fraudulent tax return using your information. This step is especially useful heading into tax season.
Applying is free and can be done directly through the IRS website. Once enrolled, you will need the PIN each year to file your taxes, which helps block unauthorized submissions. Given the sensitivity of the data exposed in this breach, this extra safeguard is worth the modest effort it requires.
Get a Free Case Review
Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.
