Doctor’s Choice Home Care Data Breach Exposes Electronic Medical Records

Published: 7 October 2026
Healthcare data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: September 2026

Doctor’s Choice Home Care, a Texas home healthcare provider, confirmed a hacking incident that exposed electronic medical records and network server data for 14,333 patients. The breach was reported to federal and state regulators in 2026. Affected individuals should monitor credit reports, watch for phishing, and review medical records for signs of fraud.

CompanyDoctor’s Choice Home Care
IndustryHealthcare
Data Types ExposedFull Names, Medical Record Information, Treatment and Diagnosis Details, Health Insurance Information, Dates of Service, Contact Information
People Affected14,333 individuals
Attack MethodHacking/IT Incident
Regulators NotifiedVermont Attorney General, HHS Office for Civil Rights

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Doctor’s Choice Home Care Data Breach?

Doctor’s Choice Home Care, a home healthcare provider based in Texas, has disclosed a data breach affecting thousands of patients. The company, formally known as Applied Healthcare Nursing Division, Inc. d/b/a Doctor’s Choice Home Care, filed a breach notification with the U.S. Department of Health and Human Services Office for Civil Rights in September 2026. According to that filing, the incident involved a hacking or IT security event that compromised sensitive patient data.

The breach notification identifies the location of the exposed information as an electronic medical record system and a network server. This suggests that attackers gained unauthorized access to core systems used to store and manage patient health data. The exact date the breach was discovered has not been publicly disclosed. As a result, the full timeline of how long the intrusion lasted remains unclear to the public.

Because this incident falls under the category of a hacking or IT incident, it likely involved unauthorized access to the organization’s digital infrastructure rather than a lost device or paper record. Following discovery, Doctor’s Choice Home Care took steps to investigate the scope of the compromise. The company also moved to meet its legal obligations under federal and state breach notification laws.

In addition to notifying the HHS Office for Civil Rights, the organization filed a separate notification with the Vermont Attorney General in August 2026. Filing with multiple regulators often happens when a breach affects residents across several states. This points to a broader footprint beyond Texas, where the company is headquartered.

Who was affected?

The breach notification states that 14,333 individuals were affected by this incident. These individuals are believed to be patients or clients of Doctor’s Choice Home Care who received in-home nursing or healthcare services. Because the exposed data lived in an electronic medical record system, the people affected are most likely current or former patients of the organization.

It has not been publicly disclosed whether employees, caregivers, or other third parties were also affected. Similarly, the exact geographic reach of impacted individuals beyond Texas and Vermont is not confirmed. However, given that home healthcare agencies often serve elderly and medically vulnerable populations, affected individuals may include people with ongoing health conditions. This group can be especially vulnerable to the downstream effects of a data breach, including targeted scams.

What Information Was Potentially Exposed?

The breach notification filed with HHS does not provide an itemized list of every data field exposed. However, because the breach involved an electronic medical record system and a network server, the exposure is likely to include a range of sensitive personal and health details. Patients of a home healthcare provider typically have extensive records on file, covering both medical and identifying information.

  • Full names
  • Medical record information
  • Treatment and diagnosis details
  • Health insurance information
  • Dates of service or appointment history
  • Contact information such as addresses and phone numbers

Because this was a healthcare provider, the exposure of medical record data raises distinct risks beyond typical identity theft. For example, criminals can use stolen health information to commit medical identity fraud. This can involve submitting fraudulent insurance claims or obtaining medical services using a victim’s identity, which can corrupt a person’s actual medical history.

In addition, when personal identifiers are exposed alongside health records, the risk of targeted phishing increases significantly. Scammers often use real details from medical records to craft convincing messages that impersonate healthcare providers or insurers. As a result, affected individuals should treat any unexpected calls or emails referencing their care with caution, even if they appear legitimate.

What is the company doing?

Doctor’s Choice Home Care responded to the incident by filing official breach notifications with regulators, a step required under federal and state law. The company submitted its report to the HHS Office for Civil Rights in September 2026, detailing the scope and nature of the breach. This filing is part of the organization’s legal obligation under the Health Insurance Portability and Accountability Act, which governs how healthcare entities must respond to data breaches.

In addition to the federal filing, Doctor’s Choice Home Care also notified the Vermont Attorney General in August 2026. This indicates the company followed through on multi-state notification requirements. These filings typically trigger a broader public record of the breach, even when the organization does not release extensive public statements beyond the regulatory filings themselves.

The specific remediation steps taken internally, such as system hardening or staff retraining, have not been publicly detailed. Likewise, it is not confirmed whether the company is offering credit monitoring or identity protection services to affected individuals. Patients who believe they may be affected should watch for a direct notification letter, which would typically outline any protective services offered.

What Should Affected Individuals Do?

Monitor Your Credit Reports Regularly

Affected individuals should begin checking their credit reports for unfamiliar accounts or inquiries. You can request free copies from each of the three major credit bureaus. Reviewing these reports regularly makes it easier to catch suspicious activity early.

Because medical identity theft can take longer to surface than financial fraud, ongoing vigilance matters. For instance, a fraudulent account tied to medical billing may not appear on a standard credit report right away. Therefore, individuals should also request an explanation of benefits from their health insurer to confirm all listed services were legitimate.

Watch for Phishing and Scam Attempts

Given that this breach involved medical records, scammers may use real treatment details to appear credible. Be cautious of calls, texts, or emails referencing your care at Doctor’s Choice Home Care. Avoid clicking links or sharing personal information unless you can verify the sender independently.

If you receive a suspicious message, contact the organization directly using a verified phone number. Never use contact details provided within the suspicious message itself. This simple step can prevent you from being misled by a convincing but fraudulent request.

Consider a Fraud Alert or Credit Freeze

Because the breach may have exposed identifying information, placing a fraud alert on your credit file is a reasonable precaution. A fraud alert requires lenders to take extra steps to verify your identity before approving new credit. This can slow down or stop identity thieves attempting to open accounts in your name.

For stronger protection, you can also place a credit freeze with each bureau. A freeze restricts access to your credit file entirely until you lift it. This option is free and can be lifted temporarily whenever you need to apply for credit yourself.

Protect Your Medical Identity

Because electronic medical records were involved, review any statements from your healthcare providers and insurer closely. Look for services or prescriptions you do not recognize. Report any discrepancies to your provider and insurer immediately.

In addition, consider requesting a copy of your medical records to confirm their accuracy. This can help you spot unauthorized changes or entries tied to medical identity fraud. If you find evidence of misuse, document everything and consider speaking with a data breach attorney about your options.

Seek Legal Guidance if You Suspect Harm

If you experience financial loss, medical billing errors, or identity theft tied to this breach, consulting an attorney may help. Many data breach attorneys offer free case evaluations to determine whether you have a valid claim. This can clarify what compensation or remedies may be available to you.

Furthermore, affected individuals sometimes qualify to join a class action lawsuit related to a breach like this one. Acting promptly can be important, since legal claims are often subject to filing deadlines. Speaking with an attorney early ensures you do not miss an opportunity to pursue compensation.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



More Information

View the public data breach notification listing from Vermont Attorney General

View the public data breach notification listing from HHS Office for Civil Rights

Related Data Breaches

Browse all recent data breaches →