Call-on-Doc, Inc. Data Breach Exposes Protected Health Information

Published: 20 September 2026
Healthcare data breach illustration
Breach Discovery: December 2025Breach Notification: August 2026

Call-on-Doc, Inc. discovered in December 2025 that an unauthorized party accessed its network between December 22, 2025 and January 3, 2026, potentially exposing patients’ protected health information. The company confirmed this in August 2026 and began notifying affected individuals. If you received a notice, place a fraud alert on your credit file and monitor your health insurance statements for suspicious claims.

CompanyCall-on-Doc, Inc.
IndustryHealthcare
Data Types ExposedPatient Names, Medical Treatment or Consultation Records, Prescription Information, Health Insurance Details, Protected Health Information
People AffectedNot Publicly Disclosed
Attack MethodUnauthorized Network Access
Regulators NotifiedNot Publicly Disclosed

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Call-on-Doc, Inc. Data Breach?

Call-on-Doc, Inc. has notified patients about a cybersecurity incident that led to unauthorized access to its computer network. The company operates in the telehealth space, and it discovered the intrusion in December 2025. According to its notification letter, an unauthorized party gained access to its systems and potentially viewed or copied protected health information.

Call-on-Doc says the unauthorized access occurred between December 22, 2025, and January 3, 2026. This means the intruder may have had access to internal systems for close to two weeks. As a result, the company later determined that certain patient data stored on its network could have been exposed during that window.

Once the company detected the suspicious activity, it moved quickly to contain the threat. Call-on-Doc took some systems offline to limit further damage. It then brought in outside forensic specialists to investigate the scope of the incident and figure out exactly what information may have been accessed.

That investigation took several months to complete. Call-on-Doc confirmed on August 19, 2026, that protected health information had potentially been accessed or acquired by the unauthorized party. Because forensic reviews of this kind require detailed analysis of affected systems, the gap between discovery and confirmation is not unusual for incidents involving healthcare data.

Who Was Affected?

The people affected by this incident are patients who used Call-on-Doc’s telehealth services. Because the exposed data was described as protected health information, this breach likely affects individuals who sought medical consultations, prescriptions, or related care through the company’s platform.

Call-on-Doc has not publicly disclosed the exact number of individuals affected by this breach. However, the company did file formal notice with regulators, which suggests the incident was significant enough to trigger mandatory reporting obligations.

It is not yet clear whether the breach affected patients across the entire country or was limited to specific regions. Since Call-on-Doc provides remote medical services, its patient base may span multiple states. This broadens the population of people who should pay attention to this notification.

What Information Was Potentially Exposed?

Call-on-Doc’s notification letter confirms that protected health information was the primary category of data involved in this breach. While the letter does not spell out every specific data element in the excerpt available to the public, protected health information can include a wide range of sensitive details tied to a patient’s medical history and care.

Based on the nature of protected health information generally, and the type of data telehealth companies typically store, the exposed categories may include:

  • Patient names
  • Medical treatment or consultation records
  • Prescription information
  • Health insurance details
  • Other information tied to healthcare visits through the platform

Even without financial account numbers or Social Security numbers explicitly listed, exposed medical information carries real risk. For example, criminals can use stolen health data to file fraudulent insurance claims or obtain medical services under someone else’s identity. This type of fraud can be difficult to detect because it does not always show up on a standard credit report.

In addition, medical identity theft can lead to inaccurate information appearing in a victim’s health records. This could affect future treatment decisions. Because of this, patients affected by this breach should treat the incident seriously, even though Call-on-Doc says it has no evidence of financial fraud or identity theft resulting from the incident so far.

What Is the Company Doing?

As soon as Call-on-Doc identified the unauthorized access, it took immediate steps to contain the threat. The company disabled certain systems to prevent further intrusion. It then hired cybersecurity professionals to conduct a full forensic investigation into the incident.

Following the investigation, Call-on-Doc sent written notification letters to affected individuals. The company also set up a dedicated call center through Cyberscout to answer questions from patients. This response line remains available for 90 days from the date of the notification letter, Monday through Friday, from 8:00 am to 8:00 pm Eastern time.

Call-on-Doc also filed formal notification regarding this incident with the California Attorney General. This filing is part of the company’s broader effort to comply with state breach notification laws. In its letter, Call-on-Doc emphasized that protecting patient data remains a top priority going forward.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Affected individuals should regularly check their credit reports for signs of suspicious activity. Under federal law, you can request one free credit report every 12 months from each of the three major credit bureaus. You can request these reports through annualcreditreport.com or by calling 1-877-322-8228.

When reviewing your reports, look closely for accounts you did not open or credit inquiries you do not recognize. If you spot anything unusual, contact the credit bureau immediately. Because early detection makes a real difference, this step should not be delayed.

Place a Fraud Alert or Credit Freeze

Given that this incident involved sensitive personal data, placing a fraud alert on your credit file is a smart precaution. A fraud alert requires creditors to verify your identity before opening new accounts in your name. You can place a one-year fraud alert for free by contacting any one of the three major credit bureaus, since they are required to notify the other two once you do.

For added protection, consider placing a security freeze on your credit file as well. A security freeze blocks lenders from accessing your credit report entirely, which makes it much harder for identity thieves to open accounts. You will need to contact Equifax, Experian, and TransUnion individually to place a freeze, and each will provide a PIN you should keep in a safe place.

Protect Your Medical Information

Because this breach involved protected health information, patients should also watch for signs of medical identity theft. Review any statements from your health insurance provider closely. If you notice claims for services you never received, contact your insurer right away.

In addition, only share your health insurance information with trusted providers and family members covered under your plan. This reduces the chance that stolen data could be combined with other misused credentials. If you find inaccurate information in your medical records, request corrections from your provider as soon as possible.

Stay Alert for Phishing Attempts

After a healthcare data breach, scammers often use stolen information to craft convincing phishing emails or phone calls. These messages may pretend to be from Call-on-Doc, your insurance company, or even a credit bureau. Be cautious of unexpected messages asking for personal details or payment.

Never click links or provide sensitive information in response to unsolicited communications. Instead, verify the source directly by visiting the official website or calling a known customer service number. This simple habit can prevent a lot of downstream harm.

Consider Consulting a Data Breach Attorney

If you received a notification letter from Call-on-Doc, you may want to speak with an attorney who focuses on data breach cases. An attorney can help you understand your legal options and whether you qualify for compensation. Many offer free initial consultations, so there is little risk in asking questions.

Because deadlines for legal claims can vary by state, it is wise to act sooner rather than later. A quick conversation with a qualified attorney can clarify what evidence you need and what steps come next. This is especially important if you later discover signs of identity theft or medical fraud tied to this incident.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



Related Data Breaches

View the full list of tracked data breaches →