Terry J. Dubrow, MD, A Medical Corporation, a Newport Beach, California-based plastic surgery practice, recently disclosed that an unauthorized actor gained access to its computer network and obtained sensitive patient information. Medical providers that collect Social Security numbers, medical records, and other sensitive personal data have a responsibility to protect that information from unauthorized access.
Terry J. Dubrow, MD’s Data Breach Investigation
According to a notification letter filed with the California Attorney General, Terry J. Dubrow, MD, A Medical Corporation (referred to in the letter as “the Practice”) was contacted by an unauthorized actor who claimed to have gained access to portions of the Practice’s digital environment. Upon learning of the claim, the Practice states that it immediately took steps to secure its systems and engaged forensic experts to investigate the scope of the intrusion. That investigation determined that an unauthorized actor had accessed a portion of the Practice’s network beginning on January 16, 2025, and acquired certain data maintained by the Practice during that time.
The Practice then conducted what it describes as a prompt review of the acquired data to determine what information was involved and to identify the specific individuals whose information was contained in the affected files. On July 27, 2026, the Practice determined that some of a given patient’s personal information had been accessed and acquired without authorization. The Practice has stated that, as of the date of its notification letter, it has no evidence that any of the affected information has actually been misused or publicly disclosed, and that it believes the incident has been contained. The Practice also reported the matter to the Federal Bureau of Investigation and began offering affected individuals complimentary identity protection services through IDX.
Breaches involving medical and cosmetic surgery practices have become an increasingly common target for cybercriminals, largely because these practices maintain a uniquely valuable combination of data: government-issued identification numbers, Social Security numbers, and detailed medical records, including treatment history and diagnostic imaging. Unlike a payment card number, which can be canceled and reissued, a person’s Social Security number and medical history cannot simply be replaced once exposed, which is part of why healthcare-sector breaches are considered especially high-risk for the people affected.
When a network intrusion combines identity-verification data such as Social Security numbers and driver’s license or state ID numbers with medical information such as prescription and procedure records, the combination can be exploited in more than one way. Fraudsters can attempt to open new lines of credit, file fraudulent tax returns, or apply for government benefits using a stolen identity, while separately exposed medical details can be used to craft convincing, targeted phishing attempts that reference a person’s actual treatment history to appear legitimate. This is one reason notification letters like the one issued by the Practice typically recommend both traditional credit-monitoring steps and heightened vigilance against unsolicited contact referencing personal medical details.
The gap between when unauthorized access is believed to have begun in January 2025 and when the Practice ultimately notified affected individuals in August 2026 is not unusual for incidents of this type. Determining precisely whose data was affected, and what specific data elements were involved for each individual, generally requires a lengthy forensic review process before a covered entity can satisfy state and federal notification requirements. Organizations are generally expected to notify affected individuals without unreasonable delay once an investigation is complete, but the law also recognizes that legitimate investigative needs can extend the practical notification timeline.
When Did This Breach Occur?
The Practice states that an unauthorized actor first accessed its network on January 16, 2025. Following its investigation, the Practice determined on July 27, 2026, that a given patient’s personal information had been included among the data accessed and acquired. Notification letters describing the incident began going out to affected individuals on or around August 13, 2026, more than a year and a half after the network intrusion is believed to have begun.
What Information Was Breached?
According to the Practice’s notification letter, the data acquired by the unauthorized actor included patients’ names along with information contained in their patient charts. Depending on what was provided to the Practice or a referring physician, this could include a patient’s driver’s license or state identification number, phone number, mailing address, email address, Social Security number, and medical information such as date of birth, prescription information, treatment information, procedure images, and x-rays. The Practice has not indicated that all patients had every category of information exposed; the specific data elements involved may vary by individual.
What You Can Do
The Practice is offering affected individuals complimentary identity protection services through IDX, including credit monitoring, for a period of time following the incident. If you received a notification letter from Terry J. Dubrow, MD, A Medical Corporation, consider taking the following steps:
- Enroll in the complimentary identity protection services referenced in your notification letter before the stated enrollment deadline.
- Regularly review your financial account statements and credit reports for unfamiliar activity.
- Consider placing a fraud alert or a security freeze on your credit file with each of the three major credit reporting agencies.
- Be cautious of unsolicited calls, texts, or emails that reference your medical history or treatment, as this information may have been exposed.
- Report any suspected identity theft to local law enforcement, your state Attorney General, or the Federal Trade Commission.
File a Data Breach Lawsuit Against Terry J. Dubrow, MD
If your personal or medical information was compromised as a result of this data breach, you may have legal options available to you. Companies and medical practices that collect and store sensitive personal data are expected to implement reasonable safeguards to protect it, and a failure to do so can form the basis of a legal claim on behalf of affected individuals.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.