Three Oaks Hospice, Incorporated, a Texas hospice business associate, notified federal regulators in September 2026 of a hacking incident involving email accounts. The breach affected 36,622 individuals and may have exposed patient health information and contact details. Anyone potentially affected should monitor credit reports, watch for medical identity theft, and remain alert for phishing attempts referencing their healthcare details.
| Company | Three Oaks Hospice, Incorporated |
|---|---|
| Industry | Healthcare |
| Data Types Exposed | Patient Names, Health Diagnosis or Treatment Information, Hospice or Care Plan Details, Dates of Service, Contact Information, Insurance or Billing Details |
| People Affected | 36,622 individuals |
| Attack Method | Hacking/IT Incident |
| Regulators Notified | HHS Office for Civil Rights |
Were you affected by this breach?
You may be owed compensation.
Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.
Check if you qualify — free reviewWhat Happened in the Three Oaks Hospice, Incorporated Data Breach?
Three Oaks Hospice, Incorporated, a Texas-based business associate in the hospice care field, has disclosed a data breach that compromised sensitive patient information. The company filed a formal notification with the U.S. Department of Health and Human Services Office for Civil Rights in September 2026. According to that filing, the incident involved unauthorized access to email accounts containing personal and health-related data.
The breach has been classified as a hacking or IT incident. This means an outside party gained unauthorized access to the organization’s systems rather than the exposure resulting from a lost device or an internal error. The specific point of entry and the timeline of the intrusion have not been publicly disclosed.
Because Three Oaks Hospice, Incorporated operates as a business associate, it likely handles health information on behalf of other healthcare providers. As a result, the breach could ripple outward to patients connected to multiple hospice or medical organizations. The exact discovery date of the breach has not been publicly disclosed, though the notification to regulators came in September 2026.
Following discovery, the organization would typically have launched an internal investigation to determine the scope of the compromise. However, the filing summary does not detail specific forensic steps taken. What is confirmed is that email was the location of the breached information, suggesting the attacker accessed one or more email accounts or mailboxes containing patient records.
Who was affected?
The breach notification filed with HHS states that 36,622 individuals were affected. This group likely includes current and former hospice patients, along with potentially their family members or caregivers whose information appeared in email correspondence. Because hospice care often involves end-of-life planning, some of the affected individuals may no longer be living, meaning their next of kin could also be impacted by this exposure.
Given that Three Oaks Hospice, Incorporated is based in Texas, the majority of affected individuals are likely located in that state. That said, the filing does not specify whether the impacted population extends beyond Texas. In addition, the notification does not clarify whether employees of the organization were also affected, or whether the breach was limited strictly to patient-related data.
Because hospice services typically serve elderly and seriously ill patients, this population may be especially vulnerable to the downstream effects of a data breach. Many affected individuals may also rely on caregivers to help manage any necessary response, which could complicate efforts to detect fraud or respond to notifications in a timely manner.
What Information Was Potentially Exposed?
The HHS filing identifies email as the location of the breached information, which commonly includes protected health information alongside identifying details. While the filing does not provide an exhaustive breakdown of every data element involved, breaches of this type in the hospice and healthcare sector frequently expose the following categories.
- Patient names
- Health diagnosis or treatment information
- Hospice or care plan details
- Dates of service
- Contact information, including addresses and phone numbers
- Potentially insurance or billing details
Because this incident involves protected health information, the risk to affected individuals extends beyond typical identity theft concerns. Medical identity theft is a genuine risk whenever diagnosis or treatment details are exposed. Fraudsters can use this information to submit fraudulent insurance claims, obtain medical services under someone else’s name, or craft highly convincing phishing messages that reference real treatment details.
In addition, exposed contact information can be used for targeted scams. For example, a scammer could pose as a hospice provider or insurance representative to extract further sensitive details from a worried family member. Because hospice patients are often older adults, this population can be disproportionately targeted by scammers posing as trusted healthcare contacts. As a result, vigilance from both patients and their families is especially important following this type of breach.
What is the company doing?
Three Oaks Hospice, Incorporated took the step of formally notifying the HHS Office for Civil Rights about this hacking incident, as required under HIPAA breach notification rules. This filing itself confirms that the organization has acknowledged the breach to federal regulators. The company filed its notification with the HHS Office for Civil Rights on September 17, 2026.
Beyond the regulatory filing itself, the publicly available summary does not provide further detail about remediation steps, security upgrades, or whether affected individuals have received direct notification letters. It also does not specify whether credit monitoring or identity protection services have been offered to those affected. Individuals concerned about their specific exposure should watch for a direct notification letter from the organization, which would typically include more specific guidance.
What Should Affected Individuals Do?
Monitor Your Credit Reports
Affected individuals should request copies of their credit reports and review them closely for unfamiliar accounts or inquiries. You can obtain free credit reports from each of the three major credit bureaus on a regular basis. Checking these reports regularly makes it easier to catch suspicious activity early.
Because medical and billing information was potentially involved in this breach, fraudulent activity may not always appear as a typical credit account. For example, some medical identity theft shows up as unfamiliar insurance claims rather than new credit lines. Therefore, it also helps to review any insurance statements or explanation-of-benefits notices for unrecognized services.
Consider a Fraud Alert or Credit Freeze
Given the sensitive nature of hospice-related data, affected individuals may want to place a fraud alert or credit freeze on their credit files. A fraud alert requires creditors to take extra steps to verify your identity before opening new credit. A credit freeze goes further by restricting access to your credit file entirely until you choose to lift it.
Both options are free to set up through each credit bureau. Because older adults and their families are often targeted after healthcare breaches, this step can provide meaningful peace of mind. It is a relatively quick process that can prevent significant financial harm down the line.
Watch for Medical Identity Theft
Because this breach involved health-related information, affected individuals should stay alert for signs of medical identity theft. This can include unfamiliar medical bills, unexpected collection notices, or insurance denials for services you never received. If something looks unfamiliar, contact your insurance provider immediately to dispute it.
In addition, consider requesting an accounting of disclosures from your healthcare providers. This record shows who has accessed or received your health information. Reviewing this accounting can help you spot unauthorized use of your medical records before it causes further harm.
Stay Alert for Phishing Attempts
Because email was the location of the breached information, there is a heightened risk of follow-up phishing attempts using details from the stolen messages. Be cautious of any email, text, or phone call asking you to confirm personal details or click a link. Legitimate healthcare providers rarely request sensitive information this way.
Instead, verify any suspicious communication by contacting the organization directly using a phone number you find independently, not one provided in the suspicious message. This simple step can prevent a secondary scam from succeeding. If you are unsure whether a message is legitimate, it is always safer to delete it and reach out independently.
Consult a Data Breach Attorney
Finally, affected individuals may want to speak with a data breach attorney to understand their legal options. Many attorneys offer free consultations to review whether you qualify for compensation related to a healthcare data breach. Because laws and deadlines vary, getting informed early can help protect your rights.
An attorney can also help you understand whether a class action lawsuit has been filed or may be filed related to this incident. This guidance can be especially valuable if you experience financial losses or identity theft linked to the breach. Acting sooner rather than later is generally recommended, since legal claims often have filing deadlines.
Get a Free Case Review
Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.
More Information
View the public data breach notification listing from HHS Office for Civil Rights
