Were you recently affected by a data breach?

LeMaitre Vascular Data Breach

LeMaitre Vascular, Inc. reported a data breach to the Vermont Attorney General’s Office affecting individuals whose Social Security numbers, government ID numbers, and health records may have been exposed. Learn what happened and your legal options.

LeMaitre Vascular
Date of Breach: Reported to the Vermont Attorney General's Office on September 18, 2026
CAU logo

Who was affected:

Clients of LeMaitre Vascular

Impacted Data:

Social Security numbers, government-issued ID numbers, health records

LeMaitre Vascular, Inc., a Burlington, Massachusetts medical device company that designs and markets vascular surgery products, reported a data breach to the Vermont Attorney General’s Office on September 18, 2026. The filing confirms that sensitive personal information, including Social Security numbers, government-issued ID numbers, and health records, was involved in the incident. Companies that collect and store this kind of sensitive data have a responsibility to protect it from unauthorized access, and when that protection fails, the people whose information is exposed deserve to know what happened and what is being done about it.

LeMaitre Vascular’s Data Breach Investigation

According to the notice filed with the Vermont Attorney General’s Office, LeMaitre Vascular disclosed that at least two Vermont residents had their personal information compromised in a security incident. The company’s filing lists the categories of data involved as Social Security numbers, government-issued ID numbers, and health records, three of the most sensitive categories of personal information a company can hold. Vermont’s breach notification law requires companies to report incidents like this in the most expedient time possible and without unreasonable delay, generally no later than 45 days after discovery, so that residents and regulators can track how the company responded once the breach was identified.

LeMaitre Vascular has not publicly disclosed the specific cause of this incident, how the unauthorized access occurred, or the exact dates on which the breach itself took place and was later discovered. As is common with early-stage breach disclosures, Vermont’s public summary of the filing does not include the company’s full breach notification letter, since the state’s Attorney General’s Office no longer posts full PDF copies of breach notices to comply with digital accessibility standards for government websites. The full extent of the breach, including whether more than the two Vermont residents currently identified were affected in other states, may not be clear until LeMaitre Vascular provides additional public disclosures or files supplemental notices as its investigation continues.

Medical device and healthcare-adjacent companies are increasingly common targets for data breaches because they routinely handle a combination of highly sensitive data types in one place, financial account information, government identification numbers, and protected health information, that together create outsized value for identity thieves and fraudsters. A single successful intrusion into a company’s systems can expose records that would otherwise require separate attacks against a bank, a government agency, and a healthcare provider to obtain. This combination is exactly what makes health-adjacent data breaches like this one particularly concerning for the people affected, since the exposed information can be used for a wide range of fraudulent purposes well beyond simple credit card fraud.

When Social Security numbers, government ID numbers, and health records are exposed together, affected individuals face a materially higher risk of long-term identity theft, medical identity fraud, and government benefits fraud than they would from a breach involving financial data alone. Medical identity theft in particular can be difficult to detect and unwind, since a fraudulent claim filed using a stolen identity can affect a victim’s medical records and insurance coverage long after the initial breach, sometimes without the victim discovering the misuse until they are denied coverage or billed for services they never received. This is one of the reasons that state legislatures like Vermont’s have specifically categorized health records and government ID numbers as sensitive personal information requiring mandatory notification, separate from ordinary financial data.

The medical device sector in particular has become an attractive target for cybercriminals in recent years, as companies in this space frequently maintain interconnected systems spanning manufacturing operations, sales and distribution networks, and patient or customer records tied to their devices and services. This connectivity, while useful for business operations, can also create additional entry points that attackers attempt to exploit. Notification timelines under state breach laws like Vermont’s are designed to give regulators and the public a way to track how quickly a company identifies and responds to an intrusion once it is discovered, even when the company’s own investigation into the root cause is still ongoing.

Companies that experience a breach involving this data profile typically face a lengthy period of investigation and remediation, and the timeline for full public disclosure of scope, cause, and affected individuals can extend well beyond the initial regulatory filing. Affected individuals are generally advised not to wait for a company’s investigation to conclude before taking protective steps of their own, since the earliest window after a breach is often when stolen data is most actively used or sold.

When Did This Breach Occur?

LeMaitre Vascular’s notification to the Vermont Attorney General’s Office is dated September 18, 2026. The company has not publicly disclosed the specific date on which the underlying security incident occurred or the date on which it was discovered internally. Vermont’s breach notification statute requires covered entities to report a breach to the Attorney General’s Office and to notify affected residents in the most expedient time possible, and without unreasonable delay, but no later than 45 days after discovery of the breach.

What Information Was Breached?

Based on LeMaitre Vascular’s filing with the Vermont Attorney General’s Office, the categories of information involved in this breach include Social Security numbers, government-issued identification numbers, and health records. The company has not publicly specified which additional data elements, if any, were involved beyond these categories, or whether the affected individuals’ names were also exposed alongside this data.

What You Can Do

If you believe you may have been affected by the LeMaitre Vascular data breach, consider taking the following steps to protect yourself:

  • Review any breach notification letter you receive from LeMaitre Vascular carefully and follow any specific instructions it provides.
  • Place a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, and TransUnion) to make it harder for someone to open new accounts in your name.
  • Monitor your credit reports, bank statements, and health insurance explanation-of-benefits statements closely for unfamiliar activity.
  • Watch for signs of medical identity theft, such as unfamiliar medical bills, collection notices for services you did not receive, or denials of coverage for reasons you do not recognize.
  • Consider enrolling in any free credit monitoring or identity protection services LeMaitre Vascular may offer to affected individuals.
  • Be cautious of phishing emails, calls, or texts referencing this breach, as scammers often use news of a breach to trick victims into revealing further personal information.

File a Data Breach Lawsuit Against LeMaitre Vascular

If you were notified that your personal information was compromised in the LeMaitre Vascular data breach, you may have legal options available to you. Companies that collect sensitive personal information, including Social Security numbers, government ID numbers, and health records, are expected to maintain reasonable security measures to protect that data from unauthorized access.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Reported incident occurred July 31, 2026; notification sent September 18, 2026
Date of Breach: Alleged incident reported to have occurred August 28, 2026; publicly reported September 17, 2026
Date of Breach: Reported to the Vermont Attorney General's Office on September 18, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.