Were you recently affected by a data breach?

PsychPlus Data Breach

Psychiatry of Texas PLLC (dba PsychPlus), a Houston-area mental health provider, notified the Texas Attorney General of a data breach affecting 4,565 patients. Exposed data may include names, addresses, Social Security numbers, and medical information.

PsychPlus
CAU logo

Who was affected:

Clients of PsychPlus

Impacted Data:

Name, address, Social Security number, medical information, and health insurance information.

Psychiatry of Texas PLLC, which does business as PsychPlus, a Houston-area mental health provider, has notified the Texas Attorney General’s office of a data security incident that affected thousands of patients. The company provides psychiatric and mental health services throughout the Houston metro area, meaning the information involved may include highly sensitive mental health and medical records in addition to standard personal identifiers. Healthcare providers that handle patient records carry a heightened responsibility to protect that information, and when a breach happens, patients deserve clear answers about what occurred and how it may affect them.

Psychiatry of Texas’s Data Breach Investigation

According to a filing submitted to the Texas Attorney General’s office, Psychiatry of Texas PLLC (operating as PsychPlus) disclosed a data security incident affecting 4,565 Texas residents. The filing was published at the OAG website on September 1, 2026, and states that the company notified affected individuals through both direct mail and a broadcast notice across Texas-wide media, a notification method typically used when a mailing address cannot be confirmed for every affected person or when the scale of the incident calls for wider public notice.

Psychiatry of Texas operates as PsychPlus, with clinic locations including its Willowbrook facility in the Houston metro area, and has been a participating provider in several insurance networks, including Aetna Better Health of Texas. Because the practice provides psychiatric evaluation, medication management, and related mental health services, the personal information it maintains on patients is likely to include not just contact and identification details but also sensitive health and treatment information tied to mental health diagnoses and care.

As of this writing, PsychPlus has not released a detailed public statement describing the specific cause of the incident, when it was first detected, or how long the exposure may have existed before it was identified. The Texas Attorney General filing confirms only that notice was sent to affected individuals and that the incident was significant enough to warrant both individual mailings and a public broadcast notice, methods generally reserved for breaches affecting a substantial number of people.

Attorneys who evaluate potential class action claims in data breach cases typically focus on several key questions once an incident like this becomes public: how quickly the company detected the intrusion after it began, whether it had reasonable security safeguards in place given the sensitivity of the mental health records it stores, and whether the notification to patients came within the time period required under Texas law, which generally requires notice “as quickly as possible” once a breach involving sensitive personal information is discovered.

If you received a notice from Psychiatry of Texas or PsychPlus about this incident, it’s important to hold on to that letter, as it may serve as documentation that your information was involved and could be useful if you decide to explore your legal options. Attorneys are already looking into incidents involving healthcare providers like this one, since breaches involving mental health treatment records raise particular privacy concerns beyond the risk of routine identity theft.

When Did This Breach Occur?

The exact date the underlying breach occurred has not yet been publicly disclosed. What is confirmed is that the incident was reported to the Texas Attorney General and published at the agency’s website on September 1, 2026, with notice going out to affected individuals around the same time via mail and broadcast media across Texas.

What Information Was Breached?

Per the notification filed with the Texas Attorney General, the categories of information involved in this incident include patients’ names, home addresses, Social Security numbers, medical information, and health insurance information. Because Psychiatry of Texas/PsychPlus provides psychiatric care, “medical information” in this context may include details related to mental health diagnoses, treatment history, or medication records, information that carries a heightened privacy sensitivity beyond typical financial or identifying data.

What You Can Do

If you’ve received notice that your information was part of this breach, there are steps worth taking right away. Consider placing a fraud alert or security freeze with the three major credit bureaus (Equifax, Experian, and TransUnion) to help prevent identity thieves from opening new accounts using your Social Security number. Monitor your explanation of benefits statements from your health insurer for any services you didn’t actually receive, which can be a sign your health insurance information is being misused. If Psychiatry of Texas or PsychPlus is offering complimentary credit monitoring or identity protection as part of its response, consider enrolling. Given the sensitive nature of mental health records, also be alert to any unusual contact referencing your treatment history, and report suspicious activity to local law enforcement or your state’s Attorney General.

File a Data Breach Lawsuit Against Psychiatry of Texas

If your personal or medical information was exposed in the Psychiatry of Texas (PsychPlus) data breach, you may be entitled to compensation for the harm and risk this incident has caused. Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: December 2-18, 2025
Date of Breach: December 2-18, 2025
Date of Breach: September 15, 2026 (reported)
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.