Were you recently affected by a data breach?

CallonDoc Data Breach

CallonDoc, a telehealth provider, discovered unauthorized network access in December 2025 that may have exposed patients’ names, contact details, and medical information. Affected patients are now being notified.

CallonDoc
Date of Breach: December 22, 2025 to January 3, 2026 (discovered December 28, 2025)
CAU logo

Who was affected:

Clients of CallonDoc

Impacted Data:

Names, email addresses, physical addresses, phone numbers, medical diagnosis information, medication information, and visit type

CallonDoc, a telehealth platform that connects patients with licensed doctors for virtual consultations, has notified patients of a data security incident that may have exposed sensitive personal and health information. Companies that manage protected health information on behalf of patients are expected to keep that information secure, and when a breach occurs, those affected have a right to know exactly what was exposed and what the company is doing about it.

CallonDoc’s Data Breach Investigation

According to notices filed with state regulators, CallonDoc became aware of unauthorized access to its network on December 28, 2025. The company took certain systems offline and engaged outside professionals to investigate what, if any, information was affected. That investigation later determined that protected health information may have been accessed or acquired by an unauthorized party during a window in late December 2025 and early January 2026. CallonDoc began notifying potentially affected individuals in September 2026.

Telehealth and digital health companies have become an increasingly common target for cybercriminals in recent years. These platforms typically store large volumes of protected health information, insurance details, and other sensitive personal data in centralized systems, making them an attractive target for hackers looking to harvest information that can be resold or used for fraud. The healthcare sector as a whole continues to report some of the highest numbers of reported data breaches of any industry, in part because medical records are considered especially valuable on illicit marketplaces compared to other types of personal data.

The combination of data types potentially involved in this incident, including names, contact information, and details about a patient’s medical diagnosis or treatment, can expose affected individuals to a range of risks beyond ordinary identity theft. Medical information paired with identifying details can be used to file fraudulent insurance claims, obtain prescription medications under someone else’s identity, or craft convincing phishing and social engineering attempts that reference a person’s actual health history to appear legitimate. Because this type of information cannot simply be changed the way a password or credit card number can, individuals whose medical records are exposed may face a longer tail of risk than a typical financial data breach.

Companies that experience a security incident involving protected health information are generally required under state and federal law to investigate the scope of the incident, notify affected individuals, and in many cases report the incident to state attorneys general once a certain threshold of affected residents is reached. The months-long gap that can occur between when unauthorized access is first detected and when a company completes its forensic investigation and begins notifying affected individuals is a routine part of this process, even though it can feel like an unreasonably long wait for people whose information may be at risk. That said, the length of an investigation and the adequacy of a company’s security safeguards leading up to an incident are both proper subjects of scrutiny once a breach becomes public.

When Did This Breach Occur?

CallonDoc states that unauthorized access to its network was first identified on December 28, 2025. Following an investigation, the company determined that protected health information may have been accessed or acquired by an unauthorized party between approximately December 22, 2025, and January 3, 2026. CallonDoc began sending written notifications to potentially affected individuals in September 2026.

What Information Was Breached?

Based on CallonDoc’s own notice to affected individuals, the information that may have been involved includes patients’ names, email addresses, physical addresses, phone numbers, medical diagnosis information, medication information, and visit type. Not all data elements were involved for every affected individual. CallonDoc has stated it has no evidence at this time that any exposed information has been used to commit fraud or identity theft.

What You Can Do

If you received a notice from CallonDoc, or believe you may have been affected by this incident, there are several steps you can take to help protect yourself:

  • Place a fraud alert or security freeze on your credit file with Equifax, Experian, and TransUnion.
  • Request and review a free copy of your credit report at annualcreditreport.com.
  • Monitor your health insurance explanation of benefits statements for services you don’t recognize.
  • Watch for phishing emails or calls that reference your medical history or appointment details.
  • Report any suspected fraud to your local law enforcement agency and the Federal Trade Commission.

File a Data Breach Lawsuit Against CallonDoc

If you received a data breach notification letter from CallonDoc, or discovered your personal or medical information was affected by this incident, you may have legal options available to you. Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Reported to the Vermont Attorney General's Office on September 18, 2026
Date of Breach: May 13, 2026 to July 8, 2026 (mailings); discovered July 7, 2026
Date of Breach: On or about June 22, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.