G.I. Medicine Associates, P.C. Data Breach Exposes Social Security Numbers and Health Records

Published: 18 September 2026
Healthcare data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: September 2026

G.I. Medicine Associates, P.C. disclosed a data breach that exposed patients’ Social Security numbers and health records, according to a filing with the Vermont Attorney General in September 2026. The number of people affected has not been publicly disclosed. Affected individuals should monitor credit reports, consider a credit freeze, and watch for a notification letter from the practice.

CompanyG.I. Medicine Associates, P.C.
IndustryHealthcare
Data Types ExposedSocial Security Numbers, Health Records
People AffectedNot Publicly Disclosed
Attack MethodUnspecified/Unauthorized Access
Regulators NotifiedVermont Attorney General

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the G.I. Medicine Associates Data Breach?

G.I. Medicine Associates, P.C. recently disclosed a data breach that exposed sensitive patient information. The practice filed formal notification with the Vermont Attorney General in September 2026. This filing confirmed that unauthorized individuals had gained access to files containing personal and medical data.

Details about how the intrusion occurred have not been publicly disclosed. However, healthcare providers are frequent targets of cyberattacks because their systems store both financial and medical records. As a result, patient files like these are especially valuable to criminals looking to commit identity theft or insurance fraud.

The exact date the breach was discovered has not been made public. Once the practice identified the incident, it appears to have launched a review of affected systems and records. This process likely involved determining which individuals had data involved and preparing required notifications to regulators and affected patients.

Because the investigation and notification process for healthcare data breaches can take time, some details may still be unfolding. Patients should watch for official letters from G.I. Medicine Associates confirming whether their specific information was involved.

Who was affected?

The breach appears to primarily affect patients of G.I. Medicine Associates, P.C. Anyone who received care or services through the practice could potentially have had their information exposed. This may include current patients as well as individuals who received treatment in the past.

The exact number of affected individuals has not been publicly disclosed. Therefore, it remains unclear how large the overall impact may be. In addition, it is not yet clear whether employees of the practice were also affected alongside patients.

Because medical practices often retain records for years, the population impacted could span a wide range of ages. This may include minors who received pediatric gastrointestinal care. Anyone uncertain about their status should reach out directly to the practice for confirmation.

What Information Was Potentially Exposed?

According to the breach notification, two major categories of sensitive data were involved. This combination is particularly concerning because it pairs identity-verification data with private medical details. Together, these data types create significant risk for those affected.

  • Social Security numbers
  • Health records

Social Security numbers are among the most valuable pieces of data for criminals. With this information, bad actors can open new credit accounts, file fraudulent tax returns, or apply for loans in a victim’s name. Because Social Security numbers rarely change, this type of exposure can create risk that lasts for years.

Health records exposure raises separate but equally serious concerns. Criminals can use stolen medical information to commit insurance fraud or obtain prescription drugs fraudulently. In addition, exposed health details could be used for targeted phishing scams that reference a victim’s actual medical history, making these scams more convincing and harder to detect.

What is the company doing?

In response to the breach, G.I. Medicine Associates, P.C. filed official notifications describing the incident. These filings outlined the categories of data involved. The practice appears to be working to inform affected individuals as required under applicable state laws.

The company also filed formal notification with the Vermont Attorney General. This filing is part of the standard regulatory process following a confirmed data security incident. Notably, the practice appears to have submitted related filings with the same office on more than one occasion in recent weeks, suggesting an ongoing notification effort tied to this incident.

Beyond notification, affected individuals should watch for a formal letter from the practice. This letter may include specific instructions and information about any protective services being offered. If credit monitoring or identity protection services are made available, that information should arrive directly from the practice.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Affected individuals should begin checking their credit reports regularly. This is one of the most effective ways to catch fraudulent activity early. You can request free reports from all three major credit bureaus through AnnualCreditReport.com.

Look closely for any accounts you do not recognize. In addition, watch for hard inquiries you did not authorize. Because Social Security numbers were involved in this breach, ongoing vigilance is especially important going forward.

Consider a Credit Freeze or Fraud Alert

Because Social Security numbers were exposed, placing a credit freeze is a strong protective step. A freeze prevents new creditors from accessing your credit file. As a result, it becomes much harder for criminals to open new accounts in your name.

Alternatively, a fraud alert requires creditors to take extra steps to verify your identity before extending credit. This option is less restrictive than a freeze but still adds a layer of protection. You can request either option directly through any of the three credit bureaus.

Protect Your Medical Identity

Because health records were exposed, patients should also review their medical files. Request an explanation of benefits from your insurance provider and check it closely. This can help you spot any services or treatments you did not actually receive.

If you notice unfamiliar claims, contact your insurer immediately. This may indicate someone is using your identity to obtain medical care or prescriptions. Correcting inaccurate medical records quickly can prevent complications with future treatment decisions.

Stay Alert for Phishing Attempts

Following any healthcare data breach, phishing attempts often increase. Scammers may reference real medical details to appear legitimate. Because of this, treat unexpected calls, texts, or emails asking for personal information with caution.

Never click links or share information in messages you did not expect. Instead, contact the practice directly using a verified phone number. This simple habit can prevent you from becoming a victim of a follow-up scam tied to this breach.

Know Your Legal Options

If your Social Security number or health records were exposed, you may have legal options available. Many affected individuals choose to consult a data breach attorney for a free case evaluation. An attorney can help determine whether you qualify for compensation.

Because deadlines for legal claims can vary by state, it is wise to act sooner rather than later. Waiting too long could limit your options. A quick consultation can clarify your rights without any upfront cost.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



More Information

View the public data breach notification listing from Vermont Attorney General

Related Data Breaches

Check other recent data breach notifications →