Midkiff, Muncie & Ross, P.C., a law firm, notified the Vermont Attorney General in September 2026 that a data breach exposed clients’ Social Security numbers and health records. The number of people affected has not been publicly disclosed. Affected individuals should place a fraud alert or credit freeze immediately and monitor credit reports and medical statements closely.
| Company | Midkiff, Muncie & Ross, P.C. |
|---|---|
| Industry | Other Commercial |
| Data Types Exposed | Social Security Numbers, Health Records |
| People Affected | Not Publicly Disclosed |
| Attack Method | Unspecified/Unauthorized Access |
| Regulators Notified | Vermont Attorney General |
Were you affected by this breach?
You may be owed compensation.
Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.
Check if you qualify — free reviewWhat Happened in the Midkiff, Muncie & Ross, P.C. Data Breach?
Midkiff, Muncie & Ross, P.C. recently confirmed that unauthorized parties gained access to sensitive files stored on its network. The firm disclosed the incident in a formal notification filed with the Vermont Attorney General in September 2026. As a result, the Midkiff, Muncie & Ross data breach is now a matter of public record.
According to the filing, the exposed information included Social Security numbers and health records. However, the exact date the intrusion occurred has not been publicly disclosed. This means affected individuals currently have limited detail about how long the exposure lasted before it was caught.
Because the firm operates in a legal setting, its systems likely held sensitive case files tied to clients and possibly third parties. In response to discovering the breach, the firm appears to have launched a review of its systems and files. This step is standard practice for identifying exactly whose data was involved before notifications go out.
At this stage, the public notification does not specify the attack method used to gain access. It also does not describe whether the intrusion involved ransomware, a phishing scheme, or another form of unauthorized entry. As more information becomes available, affected individuals should watch for updated notices from the firm.
Who was affected?
The population affected by this breach has not been publicly disclosed in terms of an exact number. Given that Midkiff, Muncie & Ross, P.C. is a law firm, those impacted likely include current and former clients. In some cases, breaches at legal practices also affect opposing parties or individuals named in case files.
Because health records were among the exposed data, it is likely the firm handled matters involving medical claims, personal injury, or similar legal work. As a result, affected individuals may include people whose medical histories were part of legal proceedings. It remains unclear whether employees of the firm were also affected.
The notification filed with Vermont regulators suggests at least one Vermont resident was impacted. However, law firms often serve clients across multiple states. Therefore, the true geographic scope of this breach may extend beyond Vermont, even though only one state filing has been confirmed so far.
What Information Was Potentially Exposed?
The Vermont filing specifically names two categories of exposed data. These categories carry serious risk because of how sensitive and permanent they are once compromised. Below is a summary of what the firm confirmed was involved.
- Social Security numbers
- Health records
Social Security numbers are considered one of the most valuable pieces of data for criminals. With this single identifier, a bad actor can attempt to open new credit lines, file fraudulent tax returns, or apply for loans in someone else’s name. Unlike a password, a Social Security number cannot simply be changed after exposure, which makes this type of breach especially concerning.
Health records add another layer of risk. For example, exposed medical information can be used to commit medical identity theft, where a criminal uses someone else’s identity to obtain treatment or prescriptions. This type of fraud can also corrupt a victim’s own medical records, potentially leading to dangerous treatment errors down the line. In addition, health details are often used in targeted phishing scams designed to look legitimate.
What is the company doing?
In response to the breach, Midkiff, Muncie & Ross, P.C. filed the required notification with state regulators. This filing indicates the firm is treating the incident seriously and following legal obligations for disclosure. The firm also appears to be notifying individuals whose information was involved, consistent with standard breach response procedures.
The firm filed formal notification with the Vermont Attorney General. This step is required under state breach notification laws when residents’ sensitive data is compromised. Beyond this filing, the notification does not detail whether the firm is offering credit monitoring or identity protection services to those affected.
Going forward, affected individuals should watch for a direct notification letter from the firm. This letter may include additional details about the breach and any protective services being offered. Because the public filing is limited in scope, more specifics may emerge as the investigation continues.
What Should Affected Individuals Do?
Monitor Your Credit Reports
Anyone notified of this breach should begin checking their credit reports regularly. This includes reviewing reports from all three major credit bureaus for unfamiliar accounts or inquiries. Early detection of fraudulent activity can prevent more serious financial damage later.
You can request free credit reports through AnnualCreditReport.com. Because Social Security numbers were exposed, this step is especially important. In addition, consider spacing out your requests across the year so you have ongoing visibility rather than a single check.
Consider a Fraud Alert or Credit Freeze
Given that Social Security numbers were part of this breach, placing a fraud alert or credit freeze is a strong protective measure. A fraud alert requires lenders to verify your identity before opening new credit. A credit freeze goes further by blocking access to your credit file entirely.
To set up either protection, contact one of the three credit bureaus directly. That bureau is required to notify the other two automatically. As a result, you only need to make one call or online request to activate broad protection across your credit profile.
Protect Against Medical Identity Fraud
Because health records were exposed, affected individuals should also watch for signs of medical identity theft. This includes reviewing insurance statements, called Explanation of Benefits notices, for unfamiliar treatments or providers. If something looks off, contact your insurer immediately.
In addition, request a copy of your medical records periodically to check for inaccuracies. Errors introduced by fraudulent claims can affect future medical care if left uncorrected. Reporting discrepancies quickly helps limit the damage and keeps your health record accurate.
Stay Alert to Phishing Attempts
After a breach involving sensitive personal data, scammers often follow up with targeted phishing emails or phone calls. These messages may reference real details from the breach to appear more convincing. Because of this, treat unexpected messages asking for personal information with caution.
Never click links or share information in response to unsolicited communications, even if they claim to be from the firm itself. Instead, contact the organization directly using a verified phone number or website. This simple habit can prevent a secondary scam from compounding the original breach’s harm.
Know Your Legal Options
If your Social Security number or health records were exposed in this incident, you may have legal options worth exploring. Data breach laws in many states allow affected individuals to seek compensation for damages tied to identity theft or fraud. Consulting a data breach attorney for a free case evaluation can help clarify your specific rights.
Because deadlines for filing claims vary by state and case type, acting sooner rather than later is wise. An attorney can review the details of your exposure and advise whether you qualify to join a claim. This guidance costs nothing upfront in most consultations, making it a low-risk way to understand your options.
Get a Free Case Review
Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.
More Information
View the public data breach notification listing from Vermont Attorney General
