Innovative Alternatives, Inc., a Houston-based provider of counseling, mediation and victim advocacy services, has reported a data breach affecting about 1,500 Texas residents. The report was posted to the Texas Attorney General’s public breach list on October 2, 2026.
Organizations that collect health and personal details from the people they serve have a responsibility to protect that information. When it is exposed, the people affected deserve clear answers and a path to hold the organization accountable.
Innovative Alternatives’s Data Breach Investigation
Innovative Alternatives, Inc. is a mental and relational health practice in Houston, Texas. Its team of licensed therapists, certified mediators and trainers offers counseling, trauma-focused therapy, mediation and a victim assistance program. Because the practice works with people during difficult moments in their lives, the information it keeps is often deeply personal.
On October 2, 2026, the practice reported a data security incident to the Texas Attorney General. The filing states that about 1,500 Texas residents were affected. The categories of information listed include individual names, dates of birth, health insurance information and other personal identifiers. The filing does not say how the incident happened, and the organization has not publicly explained how an unauthorized party may have reached the data.
Several important facts are not yet public. The date the incident was discovered has not been disclosed, and neither has the period during which information may have been accessible. It is also unclear whether the 1,500 figure covers only Texas residents or whether people in other states were notified separately. When a state regulator’s public list is the only source, these gaps are common, and they often close only when the organization sends individual notice letters or posts a longer statement.
Texas law requires an organization that suffers a breach involving sensitive personal information of 250 or more state residents to notify the Attorney General, and the state publishes those reports. A filing at this threshold means regulators and the public can see that a meaningful number of people were affected, even before a full account of the cause is available.
Counseling and therapy practices are an attractive target for criminals because their records can combine identity details with health insurance data. A name and date of birth alone can help someone open accounts or file false claims. Added to health insurance information, the same records can be used for medical identity theft, in which a stolen identity is used to obtain care or bill an insurer. Because mental health records are especially private, the loss of control over them can be distressing even when no fraud follows.
People who have used Innovative Alternatives for counseling, mediation, training or victim assistance should watch their mail for a notice letter, since that letter typically explains what was taken and what protections are being offered. Anyone who has received a letter, or who suspects their information was involved, should keep it and note the date it arrived.
Until the practice shares more, the confirmed record is limited to what appears in the Attorney General filing. This page will reflect the facts that are verified and will not speculate about a cause, the identity of any attacker, or whether information has been misused. If you were affected, taking the steps below now is a sensible precaution while more details emerge.
Health information breaches tend to unfold in stages. An organization first detects unusual activity, then investigates with outside specialists, and only after reviewing the affected files does it identify who must be told. That review can take weeks or months, which is why notices frequently arrive well after the underlying event. Delays of this kind are not unusual, but they leave affected people exposed for longer than they would like, which is one reason regulators set deadlines for notice.
Individuals can also learn a good deal from the type of data listed. Dates of birth cannot be changed the way a password can, so they stay useful to criminals for years. Insurance member numbers, by contrast, can often be replaced by contacting the insurer, which makes a prompt call worthwhile. Keeping that difference in mind helps people decide which protective steps matter most for their own situation.
When Did This Breach Occur?
The date the incident occurred has not been made public. Innovative Alternatives reported the breach to the Texas Attorney General on October 2, 2026, which is the only confirmed date so far.
It is not yet known when the organization first detected the problem, how long information was exposed, or exactly when notice letters were mailed. We will add those details once they are confirmed by the organization or a regulator.
What Information Was Breached?
According to the filing, the information involved includes individual names, dates of birth, health insurance information and other personal identifiers. The organization has not published a complete list of data types.
The filing does not say whether treatment notes, diagnoses or payment card details were involved. Anyone who receives a notice letter should read it closely, because it should describe the specific categories tied to that person.
What You Can Do
If you were a client of Innovative Alternatives, a few steps can reduce your risk:
- Read any notice letter carefully and keep it for your records.
- Review explanation of benefits statements from your health insurer and report any care or claims you do not recognize.
- Check your credit reports for free and consider placing a fraud alert or credit freeze.
- Be cautious with unexpected calls, texts and emails that mention your health care or insurance.
- Enroll in any credit or identity monitoring the organization offers.
File a Data Breach Lawsuit Against Innovative Alternatives
Attorneys are looking into whether people affected by the Innovative Alternatives breach may be able to bring a class action. A case like this can seek compensation for the time spent dealing with the incident, out-of-pocket costs and the risk of identity theft and medical fraud. It can also push an organization to improve how it safeguards sensitive records.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.