Were you recently affected by a data breach?

Terry J. Dubrow, MD Data Breach

Terry J. Dubrow, MD, A Medical Corporation, a Newport Beach plastic surgery practice, has disclosed that an unauthorized actor accessed its network and acquired patient data, including Social Security numbers and medical information. Affected individuals were notified in August 2026.

Terry J. Dubrow, MD
Date of Breach: Network access began January 16, 2025; discovered by the Practice and disclosed to affected individuals starting August 13, 2026
CAU logo

Who was affected:

Clients of Terry J. Dubrow, MD

Impacted Data:

Names, driver’s license or state ID numbers, phone numbers, mailing addresses, email addresses, Social Security numbers, dates of birth, prescription information, treatment information, procedure images, and x-rays

Terry J. Dubrow, MD, A Medical Corporation, a Newport Beach, California-based plastic surgery practice, recently disclosed that an unauthorized actor gained access to its computer network and obtained sensitive patient information. Medical providers that collect Social Security numbers, medical records, and other sensitive personal data have a responsibility to protect that information from unauthorized access.

Terry J. Dubrow, MD’s Data Breach Investigation

According to a notification letter filed with the California Attorney General, Terry J. Dubrow, MD, A Medical Corporation (referred to in the letter as “the Practice”) was contacted by an unauthorized actor who claimed to have gained access to portions of the Practice’s digital environment. Upon learning of the claim, the Practice states that it immediately took steps to secure its systems and engaged forensic experts to investigate the scope of the intrusion. That investigation determined that an unauthorized actor had accessed a portion of the Practice’s network beginning on January 16, 2025, and acquired certain data maintained by the Practice during that time.

The Practice then conducted what it describes as a prompt review of the acquired data to determine what information was involved and to identify the specific individuals whose information was contained in the affected files. On July 27, 2026, the Practice determined that some of a given patient’s personal information had been accessed and acquired without authorization. The Practice has stated that, as of the date of its notification letter, it has no evidence that any of the affected information has actually been misused or publicly disclosed, and that it believes the incident has been contained. The Practice also reported the matter to the Federal Bureau of Investigation and began offering affected individuals complimentary identity protection services through IDX.

Breaches involving medical and cosmetic surgery practices have become an increasingly common target for cybercriminals, largely because these practices maintain a uniquely valuable combination of data: government-issued identification numbers, Social Security numbers, and detailed medical records, including treatment history and diagnostic imaging. Unlike a payment card number, which can be canceled and reissued, a person’s Social Security number and medical history cannot simply be replaced once exposed, which is part of why healthcare-sector breaches are considered especially high-risk for the people affected.

When a network intrusion combines identity-verification data such as Social Security numbers and driver’s license or state ID numbers with medical information such as prescription and procedure records, the combination can be exploited in more than one way. Fraudsters can attempt to open new lines of credit, file fraudulent tax returns, or apply for government benefits using a stolen identity, while separately exposed medical details can be used to craft convincing, targeted phishing attempts that reference a person’s actual treatment history to appear legitimate. This is one reason notification letters like the one issued by the Practice typically recommend both traditional credit-monitoring steps and heightened vigilance against unsolicited contact referencing personal medical details.

The gap between when unauthorized access is believed to have begun in January 2025 and when the Practice ultimately notified affected individuals in August 2026 is not unusual for incidents of this type. Determining precisely whose data was affected, and what specific data elements were involved for each individual, generally requires a lengthy forensic review process before a covered entity can satisfy state and federal notification requirements. Organizations are generally expected to notify affected individuals without unreasonable delay once an investigation is complete, but the law also recognizes that legitimate investigative needs can extend the practical notification timeline.

When Did This Breach Occur?

The Practice states that an unauthorized actor first accessed its network on January 16, 2025. Following its investigation, the Practice determined on July 27, 2026, that a given patient’s personal information had been included among the data accessed and acquired. Notification letters describing the incident began going out to affected individuals on or around August 13, 2026, more than a year and a half after the network intrusion is believed to have begun.

What Information Was Breached?

According to the Practice’s notification letter, the data acquired by the unauthorized actor included patients’ names along with information contained in their patient charts. Depending on what was provided to the Practice or a referring physician, this could include a patient’s driver’s license or state identification number, phone number, mailing address, email address, Social Security number, and medical information such as date of birth, prescription information, treatment information, procedure images, and x-rays. The Practice has not indicated that all patients had every category of information exposed; the specific data elements involved may vary by individual.

What You Can Do

The Practice is offering affected individuals complimentary identity protection services through IDX, including credit monitoring, for a period of time following the incident. If you received a notification letter from Terry J. Dubrow, MD, A Medical Corporation, consider taking the following steps:

  • Enroll in the complimentary identity protection services referenced in your notification letter before the stated enrollment deadline.
  • Regularly review your financial account statements and credit reports for unfamiliar activity.
  • Consider placing a fraud alert or a security freeze on your credit file with each of the three major credit reporting agencies.
  • Be cautious of unsolicited calls, texts, or emails that reference your medical history or treatment, as this information may have been exposed.
  • Report any suspected identity theft to local law enforcement, your state Attorney General, or the Federal Trade Commission.

File a Data Breach Lawsuit Against Terry J. Dubrow, MD

If your personal or medical information was compromised as a result of this data breach, you may have legal options available to you. Companies and medical practices that collect and store sensitive personal data are expected to implement reasonable safeguards to protect it, and a failure to do so can form the basis of a legal claim on behalf of affected individuals.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Not publicly disclosed (reported via Massachusetts Attorney General filing, August 2026)
Date of Breach: June 11-17, 2026 (discovered June 15, 2026; notification began after a review completed July 30, 2026)
Date of Breach: June 15, 2026 to June 23, 2026 (identified June 22, 2026)
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.