Three Oaks Hospice of Fort Worth, a hospice care provider serving patients in the Fort Worth, Texas area, reported a data security incident affecting the personal information of thousands of individuals. The company disclosed the breach to the Texas Attorney General’s Office, as required under state law.
Organizations that handle sensitive medical and personal information have a responsibility to safeguard that data from unauthorized access, and to notify affected individuals promptly when a breach occurs.
Three Oaks Hospice of Fort Worth’s Data Breach Investigation
According to a report filed with the Texas Attorney General’s Office, Three Oaks Hospice of Fort Worth experienced a data security incident that exposed the personal information of 2,048 individuals. The company notified affected individuals by mail, through publication in print media, and by posting notice on its website, consistent with the notification methods required under Texas’s data breach notification law.
Hospice and home health providers are frequent targets for cyberattacks because they maintain large volumes of highly sensitive medical records, insurance information, and personal identifiers for vulnerable patient populations. Healthcare organizations, including smaller regional providers like Three Oaks Hospice of Fort Worth, have faced a steady rise in ransomware attacks, phishing schemes, and unauthorized network access in recent years, and hospice-specific operators are not exempt from this trend given the sensitivity and completeness of the records they hold.
When a breach involves a combination of a person’s name, Social Security number, medical information, and date of birth, the exposed data can be especially valuable to bad actors. Unlike a stolen credit card number, which can be canceled and reissued, a Social Security number and medical history are effectively permanent identifiers. This combination of data points is often sufficient to support new-account identity theft, medical identity theft, or highly targeted phishing attempts against the individuals affected.
State data breach notification laws, including the Texas Identity Theft Enforcement and Protection Act, generally require companies to notify affected residents and the state Attorney General’s Office without unreasonable delay once a breach is discovered and its scope is understood. The exact timeline between when a breach is first detected internally and when it is ultimately reported can vary significantly depending on the complexity of the forensic investigation needed to determine what data was accessed and which individuals were affected.
As with many breach disclosures filed with state regulators, the publicly available report does not include a detailed narrative of how the incident occurred or whether a specific cause has been identified. Three Oaks Hospice of Fort Worth has not publicly disclosed additional detail beyond what appears in the regulatory filing at this time.
Individuals who receive a notification letter from Three Oaks Hospice of Fort Worth, or who believe they may have been affected by this incident, are encouraged to review the notice carefully and take the protective steps outlined below.
When Did This Breach Occur?
Three Oaks Hospice of Fort Worth’s data breach was reported to the Texas Attorney General’s Office, with the report published on September 21, 2026. The publicly available regulatory filing does not specify the exact date the underlying breach occurred or the date it was first detected internally, information that is common for a filing of this type to omit. Individuals who received a direct notification letter from the company may find more specific dates described there.
What Information Was Breached?
Based on the report filed with the Texas Attorney General’s Office, the categories of information involved in this incident include the names of affected individuals, Social Security numbers, medical information, and dates of birth. The company notified the 2,048 affected individuals by U.S. Mail, by posting notice on its website or a special website, and through publication in print media. Individuals who received a direct letter from the company should review it for the complete list of information specific to their own records.
What You Can Do
If you received a notice from Three Oaks Hospice of Fort Worth, or believe your information may have been affected by this breach, consider taking the following steps:
- Read any notification letter carefully and keep a copy for your records.
- Place a fraud alert or credit freeze with the three major credit bureaus given the exposure of Social Security numbers.
- Monitor your medical bills, insurance statements, and explanation of benefits for unfamiliar charges or services.
- Request a copy of your medical records from your healthcare providers to check for inaccuracies that could indicate medical identity theft.
- Watch for phishing emails, calls, or text messages referencing this breach, and never provide personal information in response to an unsolicited message.
- Report any suspected identity theft to the Federal Trade Commission at IdentityTheft.gov.
File a Data Breach Lawsuit Against Three Oaks Hospice of Fort Worth
If you were notified that your personal or medical information was exposed in the Three Oaks Hospice of Fort Worth data breach, you may have legal options available to you. Companies entrusted with sensitive medical and personal data have a legal duty to implement reasonable safeguards to protect it, and when that duty is breached, affected individuals may be entitled to compensation.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.