Village Practice Management Company, LLC, the corporate entity behind the national primary care network known as VillageMD, recently notified state regulators of a data security incident affecting tens of thousands of individuals. The filings confirm that sensitive personal and medical information was involved.
Healthcare organizations that collect and store patients’ sensitive medical and financial information have a heightened responsibility to protect that data, given the serious consequences patients can face when it is exposed.
VillageMD’s Data Breach Investigation
According to a report filed with the Texas Attorney General’s office and published on August 4, 2026, Village Practice Management Company, LLC disclosed a data security incident affecting 25,022 Texas residents. The filing indicates that the exposed information included individuals’ names, Social Security numbers, medical information, and dates of birth. The company reported that notice was provided to affected individuals by U.S. Mail. As is typical for entries in state attorney general breach reporting databases, the filing itself does not disclose the underlying cause of the incident or the specific dates on which the breach occurred or was detected.
VillageMD, doing business through Village Practice Management Company, LLC, operates primary care clinics across numerous U.S. states, meaning a single security incident affecting its systems can result in regulatory filings in multiple states, each reflecting the number of residents of that particular state who were affected rather than the total number of people impacted nationwide. Healthcare providers remain one of the most frequently targeted sectors for data breaches because patient records typically combine several categories of high-value data, including Social Security numbers, medical diagnoses, and demographic details, all in a single record.
The combination of Social Security numbers, dates of birth, and medical information exposed in this incident creates multiple avenues of risk for affected individuals. Criminals can use Social Security numbers and dates of birth to attempt new-account fraud, apply for credit, or file fraudulent tax returns. When medical information is also exposed, there is an additional risk of medical identity theft, in which a criminal uses a victim’s identity to obtain medical services, prescriptions, or durable medical equipment, potentially leading to inaccurate entries in the victim’s own medical history or unexpected bills.
When Did This Breach Occur?
VillageMD’s report to the Texas Attorney General was published on August 4, 2026. The filing does not specify the exact dates on which the underlying breach occurred or was discovered, which is common in filings that report only the categories of compromised data, the count of affected state residents, and confirmation that notice was mailed.
What Information Was Breached?
Per the company’s filing with the Texas Attorney General, the following categories of personal information were involved: names, Social Security numbers, medical information, and dates of birth. The filing confirms that notice was provided to affected individuals via U.S. Mail. The 25,022 figure reflects Texas residents specifically; VillageMD operates in many other states and the total number of individuals affected nationwide may be higher, though a separate nationwide total has not been publicly confirmed as of this writing.
What You Can Do
If you received a notice from VillageMD or Village Practice Management Company, LLC, or believe your information may have been exposed in this incident, consider taking the following steps:
- Review the notification letter carefully and retain it for your records.
- Enroll in any free credit monitoring or identity theft protection services the company offers.
- Place a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, and TransUnion).
- Regularly review your credit reports and financial account statements for unauthorized activity.
- Review your medical bills and insurance Explanation of Benefits statements for services you did not receive.
- Be cautious of phishing calls, texts, or emails referencing this breach or your medical care.
File a Data Breach Lawsuit Against VillageMD
If your personal or medical information was exposed as a result of this incident, you may have legal options available to you. Healthcare organizations are expected to implement reasonable safeguards to protect patient data, and when those safeguards fail, affected individuals may be entitled to compensation for the harm and inconvenience caused by the exposure.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.