Normandin, Cheney & O’Neil PLLC Data Breach Exposes Social Security Numbers and Health Records

Other Commercial data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: June 2026

What Happened in the Normandin, Cheney & O’Neil PLLC Data Breach?

Normandin, Cheney & O’Neil PLLC recently filed a formal notice with the Vermont Attorney General confirming a data breach. This filing revealed that unauthorized parties gained access to sensitive personal information held by the firm. The Normandin Cheney O’Neil data breach now joins a growing list of law firm incidents affecting client and personal records across the country.

The notification does not specify the exact method attackers used to breach the firm’s systems. However, the filing confirms that several categories of highly sensitive data were involved. As a result, affected individuals now face a real risk of identity theft and fraud.

Details about how the intrusion was first discovered have not been made public. Law firms typically uncover this type of incident through internal security monitoring, third-party forensic audits, or reports of suspicious account activity. Because the firm has not released a full timeline, it remains unclear exactly when the unauthorized access began.

Following discovery, the firm appears to have launched an investigation to determine the scope of the compromise. This step is standard practice after any suspected data security incident. Consequently, the firm was able to identify which categories of personal data were affected before notifying state regulators.

Who was affected?

The notification does not state a specific number of individuals impacted by this breach. Therefore, the exact scale of the incident has not been publicly disclosed. Given that Normandin, Cheney & O’Neil PLLC operates as a legal services provider, those affected likely include current and former clients whose personal records were stored in firm systems.

Because law firms often retain highly sensitive documentation tied to legal matters, the affected population may include individuals involved in estate planning, litigation, real estate transactions, or other legal proceedings. In addition, employees of the firm could also be among those impacted. At this time, there is no indication regarding the geographic concentration of victims beyond Vermont’s regulatory filing.

What Information Was Potentially Exposed?

According to the breach notification, several sensitive categories of personal data were involved in this incident. This combination of data types creates significant exposure for anyone affected. Below are the categories confirmed in the filing.

  • Social Security numbers
  • Government ID numbers
  • Financial account codes
  • Credit and debit account information
  • Health records

This mix of data is particularly concerning because it spans both financial and medical information. For example, Social Security numbers combined with financial account codes can allow criminals to open new credit lines or drain existing accounts. Meanwhile, government ID numbers can be used to create fraudulent identification documents.

In addition, the exposure of health records raises the risk of medical identity theft. This occurs when someone uses stolen information to obtain medical services or prescriptions under another person’s name. As a result, affected individuals should watch closely for unfamiliar medical bills or insurance claims in the coming months, since this type of fraud can be harder to detect than standard financial theft.

What is the company doing?

In response to the breach, Normandin, Cheney & O’Neil PLLC filed the required notification with the Vermont Attorney General’s office. This step fulfills the firm’s legal obligation to inform regulators when residents’ sensitive data has been compromised. The filing indicates that the firm has acknowledged the incident and taken steps to comply with state breach notification laws.

Beyond the regulatory filing, specific remediation measures have not been detailed publicly. Firms in this situation typically work to secure affected systems, engage cybersecurity specialists, and review internal safeguards to prevent future incidents. However, because further details were not included in the available notification, it is not yet clear whether the firm is offering credit monitoring or identity protection services to those affected.

What Should Affected Individuals Do?

Monitor Your Credit Reports Closely

Affected individuals should request copies of their credit reports from all three major bureaus. Reviewing these reports regularly helps you catch unauthorized accounts or inquiries early. You can access free reports through AnnualCreditReport.com on a regular basis.

Because Social Security numbers were involved in this breach, the risk of new-account fraud is elevated. Therefore, checking your reports every few months, rather than just once, gives you a better chance of spotting suspicious activity before it causes lasting damage.

Consider a Credit Freeze or Fraud Alert

Given that Social Security numbers and financial account codes were exposed, placing a credit freeze is one of the strongest protective steps available. A freeze blocks lenders from accessing your credit file, which makes it much harder for criminals to open accounts in your name.

Alternatively, a fraud alert requires creditors to verify your identity before extending credit. This option is less restrictive than a freeze but still offers meaningful protection. Either way, contacting Equifax, Experian, and TransUnion directly is the fastest way to put these protections in place.

Watch for Signs of Medical Identity Theft

Because health records were part of this breach, affected individuals should review any insurance statements and medical bills carefully. Look for services or prescriptions you don’t recognize. If something seems off, contact your insurance provider immediately to dispute the charge.

In addition, requesting a copy of your medical records from your health plan can help you spot inaccuracies caused by fraudulent use of your information. Correcting these errors early prevents them from affecting future medical care or insurance coverage.

Stay Alert for Phishing Attempts

Following any data breach, scammers often use stolen information to craft convincing phishing emails or phone calls. These messages may reference real personal details to appear legitimate. As a result, you should be cautious of unexpected messages asking you to confirm account information or click on links.

Instead of responding directly, verify the sender by contacting the organization through official channels. This simple habit can prevent you from unknowingly handing over additional sensitive information to criminals.

Consult a Data Breach Attorney

If you believe your information was compromised in this incident, speaking with a data breach attorney can help clarify your legal options. Many attorneys offer free consultations to evaluate whether you may be entitled to compensation.

Because this breach involved highly sensitive categories of data, including Social Security numbers and health records, legal action may be available depending on the specific harm you experienced. An attorney can help you understand potential next steps based on your individual situation.



More Information

Official data breach notification from Vermont Attorney General

Related Data Breaches

Browse all recent data breaches →