CallonDoc, a telehealth platform that connects patients with licensed doctors for virtual consultations, has notified patients of a data security incident that may have exposed sensitive personal and health information. Companies that manage protected health information on behalf of patients are expected to keep that information secure, and when a breach occurs, those affected have a right to know exactly what was exposed and what the company is doing about it.
CallonDoc’s Data Breach Investigation
According to notices filed with state regulators, CallonDoc became aware of unauthorized access to its network on December 28, 2025. The company took certain systems offline and engaged outside professionals to investigate what, if any, information was affected. That investigation later determined that protected health information may have been accessed or acquired by an unauthorized party during a window in late December 2025 and early January 2026. CallonDoc began notifying potentially affected individuals in September 2026.
Telehealth and digital health companies have become an increasingly common target for cybercriminals in recent years. These platforms typically store large volumes of protected health information, insurance details, and other sensitive personal data in centralized systems, making them an attractive target for hackers looking to harvest information that can be resold or used for fraud. The healthcare sector as a whole continues to report some of the highest numbers of reported data breaches of any industry, in part because medical records are considered especially valuable on illicit marketplaces compared to other types of personal data.
The combination of data types potentially involved in this incident, including names, contact information, and details about a patient’s medical diagnosis or treatment, can expose affected individuals to a range of risks beyond ordinary identity theft. Medical information paired with identifying details can be used to file fraudulent insurance claims, obtain prescription medications under someone else’s identity, or craft convincing phishing and social engineering attempts that reference a person’s actual health history to appear legitimate. Because this type of information cannot simply be changed the way a password or credit card number can, individuals whose medical records are exposed may face a longer tail of risk than a typical financial data breach.
Companies that experience a security incident involving protected health information are generally required under state and federal law to investigate the scope of the incident, notify affected individuals, and in many cases report the incident to state attorneys general once a certain threshold of affected residents is reached. The months-long gap that can occur between when unauthorized access is first detected and when a company completes its forensic investigation and begins notifying affected individuals is a routine part of this process, even though it can feel like an unreasonably long wait for people whose information may be at risk. That said, the length of an investigation and the adequacy of a company’s security safeguards leading up to an incident are both proper subjects of scrutiny once a breach becomes public.
When Did This Breach Occur?
CallonDoc states that unauthorized access to its network was first identified on December 28, 2025. Following an investigation, the company determined that protected health information may have been accessed or acquired by an unauthorized party between approximately December 22, 2025, and January 3, 2026. CallonDoc began sending written notifications to potentially affected individuals in September 2026.
What Information Was Breached?
Based on CallonDoc’s own notice to affected individuals, the information that may have been involved includes patients’ names, email addresses, physical addresses, phone numbers, medical diagnosis information, medication information, and visit type. Not all data elements were involved for every affected individual. CallonDoc has stated it has no evidence at this time that any exposed information has been used to commit fraud or identity theft.
What You Can Do
If you received a notice from CallonDoc, or believe you may have been affected by this incident, there are several steps you can take to help protect yourself:
- Place a fraud alert or security freeze on your credit file with Equifax, Experian, and TransUnion.
- Request and review a free copy of your credit report at annualcreditreport.com.
- Monitor your health insurance explanation of benefits statements for services you don’t recognize.
- Watch for phishing emails or calls that reference your medical history or appointment details.
- Report any suspected fraud to your local law enforcement agency and the Federal Trade Commission.
File a Data Breach Lawsuit Against CallonDoc
If you received a data breach notification letter from CallonDoc, or discovered your personal or medical information was affected by this incident, you may have legal options available to you. Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.