An unauthorized third party accessed computer systems at Jeffrey David Reuben, M.D.’s Texas orthopedic practice between April 18 and 19, 2026, exposing names, Social Security numbers, driver’s license numbers, government IDs, and financial information for 17,017 patients. No confirmed misuse has been reported yet. Affected individuals should enroll in the offered free credit monitoring and watch their credit reports closely.
| Company | Luminis Health; Jeffrey David Reuben, M.D.; Well Child; Horizon Eye Care Laser & Eye Surgery Center |
|---|---|
| Industry | Healthcare |
| Data Types Exposed | Full Names, Social Security Numbers, Driver’s License Numbers, Government-Issued ID Numbers, Financial Information |
| People Affected | 17,017 individuals |
| Attack Method | Unauthorized Network Access |
| Regulators Notified | Delaware Attorney General |
What Happened in the Jeffrey David Reuben, M.D. Data Breach?
Jeffrey David Reuben, M.D., a Texas-based orthopedic surgeon treating patients at NW Surgery in Houston and clinics in Bellaire, has confirmed a data security incident. The Jeffrey David Reuben data breach involved unauthorized access to computer systems that stored sensitive patient records. This event is part of a broader wave of healthcare data incidents reported in the same period, alongside separate breaches at other providers.
According to the practice, the intrusion took place over a short window in April 2026. Investigators determined that an unauthorized third party gained access to systems containing patient information between April 18 and April 19, 2026. The breach discovery came shortly afterward, when the practice identified suspicious activity and began an internal review.
Once the incident was discovered, the practice brought in outside cybersecurity professionals to determine what happened and how far the intrusion reached. As a result, a full forensic investigation was launched to trace the attacker’s activity and confirm which files were accessed. This process took several months to complete.
The investigation and data review concluded around July 15, 2026. At that point, the practice confirmed which categories of patient information had actually been exposed. Because healthcare providers store highly sensitive records, this type of confirmed access raises significant concern for anyone whose information was involved.
Who was affected?
The Jeffrey David Reuben data breach affects both current and former patients of the practice. In total, 17,017 individuals had their information exposed in this incident. This means anyone who received orthopedic care from this provider in Houston or Bellaire may be included in the notification population.
Because the affected group includes former patients, some people who received care years ago could still be impacted. This is a common feature of medical record breaches, since providers often retain patient files well beyond the date of the last visit. Consequently, even individuals who no longer receive care from this practice should check whether they received a notification letter.
The source material does not indicate whether minors were among those affected. However, orthopedic practices commonly treat patients of all ages, so families should not assume their children are automatically excluded. If you receive a notification letter, it applies specifically to you or a family member in your household.
What Information Was Potentially Exposed?
The confirmed data review found that several categories of sensitive personal information were accessed during the intrusion. This information could be used to commit identity theft or financial fraud if it falls into the wrong hands. Below is the full list of exposed data types confirmed by the investigation.
- Full names
- Social Security numbers
- Driver’s license numbers
- Government-issued ID numbers
- Financial information
The combination of Social Security numbers with government identification and financial details creates a serious risk profile. In particular, this mix of data is often enough for criminals to open new credit accounts, file fraudulent tax returns, or apply for loans in a victim’s name. Because these details rarely change, the risk does not fade quickly after a breach.
In addition, driver’s license numbers can be used to create fake identification documents. This means affected individuals could face issues beyond financial fraud, including impersonation in situations that require photo identification. As a result, experts generally recommend long-term monitoring rather than a one-time check after this type of exposure.
Although the practice has stated that no confirmed misuse of the data has been identified so far, this does not guarantee future safety. Stolen data is sometimes held by criminals for months or years before being used. Therefore, ongoing vigilance remains important even if nothing suspicious has happened yet.
What is the company doing?
After confirming the scope of the incident, the practice notified affected patients and began offering support services. Specifically, the practice is providing complimentary credit monitoring and identity theft protection services for 12 months to everyone affected. This is a standard response for healthcare providers facing this type of confirmed data exposure.
In addition, the practice worked with third-party cybersecurity professionals throughout the investigation to determine the full scope of the intrusion and strengthen its systems going forward. The practice also filed a formal notification with the Delaware Attorney General, as required under applicable breach notification laws. This filing provides regulators with details about the scope and nature of the exposure.
Going forward, affected patients should watch for official notification letters that explain how to enroll in the offered protection services. Because enrollment periods are often time-limited, patients should act promptly once they receive their letter. Furthermore, patients with questions about the incident can typically follow up using contact information included in that notice.
What Should Affected Individuals Do?
Monitor Your Credit Reports Regularly
Anyone affected by the Jeffrey David Reuben data breach should begin checking their credit reports right away. You can request free reports from all three major credit bureaus and review them for accounts you don’t recognize. Doing this regularly helps you catch fraudulent activity before it causes serious financial damage.
Because Social Security numbers were exposed, criminals could attempt to open new lines of credit using your identity. For this reason, it helps to space out your free credit report requests throughout the year so you have continuous visibility. If you notice anything unusual, report it to the credit bureau immediately.
Consider a Credit Freeze or Fraud Alert
Given that Social Security numbers, driver’s license numbers, and financial information were all exposed, a credit freeze offers strong protection. A freeze blocks lenders from accessing your credit file, which stops most attempts to open new accounts in your name. This step is free and can be lifted temporarily whenever you need to apply for credit yourself.
Alternatively, a fraud alert requires creditors to take extra verification steps before approving new credit. This option is less restrictive than a freeze but still adds a meaningful layer of protection. Either way, contacting all three credit bureaus ensures your alert or freeze applies across the board.
Enroll in the Offered Credit Monitoring Services
Because the practice is offering complimentary credit monitoring and identity theft protection for 12 months, affected individuals should take advantage of this benefit. These services can alert you quickly if someone tries to misuse your information. Enrolling costs nothing and provides an added safety net during the period of highest risk.
To enroll, follow the instructions provided in your official notification letter, since it will include specific enrollment codes or deadlines. If you did not receive a letter but believe you may be affected, contact the practice directly to confirm your status. Acting quickly ensures you don’t miss the enrollment window.
Stay Alert for Phishing and Scam Attempts
After a healthcare data breach, criminals often follow up with phishing emails, calls, or texts designed to trick victims into revealing more information. Because your name and other personal details were exposed, scammers may try to appear legitimate by referencing accurate information about you. Always verify the sender before clicking links or providing any details.
If you receive a suspicious message claiming to be from the practice, a credit bureau, or a government agency, contact the organization directly using a verified phone number. Never provide Social Security numbers or financial details in response to an unexpected message. When in doubt, treat unsolicited contact with caution.
Consult a Data Breach Attorney
Given the sensitivity of the exposed data, affected individuals may want to speak with an attorney who focuses on data breach cases. A free consultation can help you understand whether you qualify for compensation. This is especially worth considering if you experience direct financial harm as a result of this incident.
An attorney can also help you understand your legal options and any relevant deadlines that may apply to your situation. Because these deadlines vary by state and case type, it helps to get informed early. Taking this step costs nothing upfront and may protect your long-term financial interests.
More Information
Official data breach notification report (PDF) from Delaware Attorney General
