What Happened in the Terry J. Dubrow, MD Data Breach?
Terry J. Dubrow, MD, A Medical Corporation, a plastic surgery practice based in Newport Beach, California, has confirmed a data breach affecting its patients. The practice learned that an unauthorized actor claimed to have broken into portions of its computer network. This claim triggered an internal review of the practice’s digital systems and files.
Investigators later traced the intrusion back to January 2025, when the outside actor first gained entry into the network. The individual remained inside the system long enough to copy files containing sensitive patient records. As a result, the practice brought in outside forensic specialists to map out exactly what happened and which files were touched.
The forensic review took considerable time to complete. The practice discovered in July 2026 that specific patient files had, in fact, been accessed and taken without permission. Because sorting out which individuals were affected required a detailed file-by-file analysis, the timeline between the original intrusion and final confirmation stretched well over a year. The practice also reported the matter to the Federal Bureau of Investigation as part of its response.
Who was affected?
The breach affects patients who received care or consultations through Terry J. Dubrow, MD, A Medical Corporation. This includes anyone whose records, charts, or intake information were stored on the practice’s network at the time of the intrusion. Because the practice serves cosmetic surgery patients, the exposed files likely include highly personal medical histories.
The exact number of affected individuals has not been publicly disclosed. However, the practice has confirmed that not every patient had the same categories of information exposed. Some records may have included only basic contact details, while others contained more sensitive medical and identification data. Patients who received a written notification letter should assume their information was part of the confirmed exposure.
What Information Was Potentially Exposed?
According to the notification sent to affected patients, the unauthorized actor obtained a wide range of personal and medical information. The specific data elements involved vary from patient to patient, depending on what was stored in each individual’s chart.
- Full names
- Driver’s license or state identification numbers
- Phone numbers
- Mailing addresses
- Email addresses
- Social Security numbers
- Dates of birth
- Prescription information
- Treatment information
- Procedure images
- X-rays
This combination of data creates serious risk because it pairs identity-verification numbers with deeply personal medical details. Someone with a stolen Social Security number and driver’s license number can attempt to open new credit accounts, file fraudulent tax returns, or apply for government benefits under another person’s name. Unlike a credit card number, a Social Security number cannot simply be canceled and replaced, so the exposure creates a long-term risk rather than a one-time problem.
In addition to financial fraud, the medical details in this breach raise a separate concern. Because the stolen files include prescription records, treatment notes, and diagnostic images, scammers could use those details to craft convincing phishing messages. For example, a fraudulent email referencing a patient’s actual procedure history might trick that person into revealing further personal information or clicking a malicious link. This makes the exposure riskier than a typical breach involving contact information alone.
What is the company doing?
Once the practice learned of the intrusion, it moved to secure its network and stop further unauthorized access. It then brought in forensic experts to determine the scope of the incident and identify which patient files were involved. This investigation ultimately confirmed the exposure in July 2026, leading to written notifications sent to patients in August 2026.
As part of its response, the practice reported the incident to the Federal Bureau of Investigation. It has also stated that it currently has no evidence that the stolen data has been misused or shared publicly, and it believes the incident has been contained. To help affected patients protect themselves, the practice is offering complimentary identity protection services through IDX, including credit monitoring, for a set period following the breach.
What Should Affected Individuals Do?
Enroll in the Free Identity Protection Services
Patients who received a notification letter should sign up for the complimentary IDX identity protection and credit monitoring services as soon as possible. These services can flag suspicious activity tied to your identity before it causes lasting damage.
Because enrollment is often subject to a deadline, check your letter for the exact cutoff date. Waiting too long could mean missing out on this free protection, so it’s worth taking a few minutes to complete the sign-up promptly.
Monitor Your Credit Reports and Financial Accounts
Given that Social Security numbers and driver’s license numbers were exposed, affected individuals should watch their credit reports closely for accounts they did not open. You can request free credit reports from each of the three major credit bureaus to check for unfamiliar activity.
In addition to credit reports, review your bank and credit card statements regularly for unauthorized charges. Because fraud can appear months or even years after a breach, ongoing vigilance matters more than a single check right after receiving your notice.
Consider a Fraud Alert or Credit Freeze
Since this breach involved Social Security numbers, placing a fraud alert or a full security freeze on your credit file is a smart precaution. A freeze blocks new creditors from viewing your credit report, which makes it much harder for someone to open accounts in your name.
You will need to contact each of the three major credit bureaus separately to set up a freeze. While this adds a small extra step whenever you apply for credit yourself, it offers strong protection against identity thieves using your stolen information.
Protect Yourself Against Medical Identity Theft
Because prescription records, treatment details, and imaging files were part of this breach, patients should also watch for signs of medical identity theft. This can include unfamiliar charges on insurance statements or bills for treatment you never received.
If you notice anything unusual, contact your insurance provider and the practice directly to flag the issue. It’s also wise to request a copy of your medical records periodically to confirm that no unfamiliar treatments have been added to your file.
Stay Alert to Phishing Attempts
Because your medical history may now be in the hands of criminals, be cautious of any unexpected calls, texts, or emails referencing your treatment or procedures. Scammers may use these real details to make their messages appear legitimate.
Never click links or share personal information in response to unsolicited messages, even if they seem to know specifics about your care. Instead, contact the practice or your provider directly using a phone number you already trust to confirm whether the message is genuine.
More Information
Official data breach notification from California Attorney General
